Repository navigation
Security Model
github-actions[bot] edited this page Oct 5, 2026
·
2 revisions
The full document is
docs/security-model.md
in the repository, versioned with the code. Summary:
- Internet → edge. Only the master proxy on the VPS is internet-facing.
- Edge → appliance. A rathole tunnel, encrypted with Noise.
- LAN → appliance. HTTPS with a self-signed certificate that you trust once. Before that, a LAN attacker can intercept first use.
-
notshared↔shared. Separate users and groups, mode-700 homes.
- Shared origin. The admin UI, Nextcloud and Forgejo share one origin. An XSS in Nextcloud or Forgejo can read the admin token, which is equivalent to root. The fix would be a separate hostname for the admin UI.
- Theft of the whole box is not defended against. The disk key is sealed to the TPM without PCR binding, so the chip releases it to any software run on that machine; only the disk on its own is unreadable. On a machine without a TPM the keyfile is on an unencrypted ESP and even the disk alone is readable.
- The audit log is not tamper-evident and does not rotate.
- Throttling is per address, so address spoofing on the LAN bypasses it.