v0.9.55-alpha — Cyber Controls: one-click SSO + MFA hardening
Cyber Controls — flip your whole TAK stack into a hardened security posture in one click, and back out just as easily.
The new Cyber Controls page adds a Standard ↔ Hardened toggle that closes the security gaps a reviewer fails a system for — then self-documents what it did.
In Hardened posture
- Per-user single sign-on with enforced multi-factor authentication on every app behind Authentik — console, Node-RED, TAK Portal, WebODM, MediaMTX, NetBird. MFA is force-enrolled at first login, so no account slips through without it.
- The admin console comes off the public internet — reachable only through authenticated SSO. The shared console password becomes an on-box break-glass recovery (used from the server shell), not a network login.
- 30-minute idle auto-logout.
- Per-user audit log — who did what, when.
- Boundary checks (read-only): firewall deny-by-default, intrusion prevention active, and TAK Tomcat exposure.
- Readiness report — a printable summary of your posture plus an editable "what to tell your security office" statement.
Safety
Every control is reversible with one click, and the on-box recovery path means hardening can never permanently lock you out — verified with a full lost-SSO recovery drill.
Not affected
TAK clients (ATAK / iTAK / CloudTAK) and TAK Server keep their native authentication — Cyber Controls governs the management surfaces, not the TAK service itself. Login screens also got plainer, on-brand wording.
Upgrade
Applied automatically — the Cyber Controls page appears in the console. The default stays Standard (no change to current behavior). When you're ready: enroll an MFA device, then flip to Hardened.