docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
docs: update wiki with latest features
- WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar,
and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs
- Analytics: document optional ClickHouse via clickhouse compose profile,
disabled banner behavior, combining with geoipupdate profile
- User Management: add Create User flow and POST /api/v1/users endpoint
- Forward Auth: add Excluded Paths section with Navidrome example
- Geo Blocking: document LAN Only (RFC1918) preset button
- mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths)
- Cloudflare DNS: simplify to redirect to DNS Provider Configuration page
- Installation Guide: document clickhouse compose profile as default analytics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
docs: add geo blocking guide and update navigation
- Create Feature-Guide-Geo-Blocking.md with full setup and rule documentation
- Add geo blocking section to Feature-Guide-Proxy-Hosts.md
- Link new guide from Home.md navigation
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>