Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Add agent & cloud hardening guides#20218

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
kanelatechnical wants to merge3 commits intonetdata:master
base:master
Choose a base branch
Loading
fromkanelatechnical:docs/agent-hardening-guide

Conversation

kanelatechnical
Copy link
Contributor

Costa requested the creation of hardening guides — two separate docs: one for the agent and one for cloud-based deployments.

Please review and feel free to correct or expand on any technical details I may not have gotten right.

These docs are intended to live under the broader "Privacy and Security" category.

@ilyam8ilyam8 requested review fromralphm andM4iteeMay 2, 2025 08:25
@ilyam8ilyam8 marked this pull request as draftMay 2, 2025 08:25
@M4itee
Copy link
Contributor

The guides are essentially correct but what I would say is that they lack some details. We talk about securing this or that but the instructions on how to exactly do that are not there - what I need to change in which file to make it happen.

@ilyam8
Copy link
Member

I think@kanelatechnical can't add more details. Can you,@M4itee?@kanelatechnical will update the wording later.

@kanelatechnical
Copy link
ContributorAuthor

@M4itee hey hey! If you like you could make a separate draft with relative notes, so I can integrate the missing info in the guides myself

@M4itee
Copy link
Contributor

I will try, do we have any ETA on this? I need to arrange my working time accordingly

@kanelatechnical
Copy link
ContributorAuthor

According to Costa this is priority, if you're working on something else that's also urgent perhaps consult with him about which should come first

M4itee reacted with thumbs up emoji

| [Netdata Cloud (SaaS)](https://app.netdata.cloud) and its web dashboard | ✓ |
| Cloud-to-Agent interactions (including Netdata Parents) | ✓ |
| Optional on-premises or private-hosted Netdata Cloud setups | ✓ |
| Netdata Agent security (covered in separate guide) | ✗ |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

We should link it when we will know what the link is going to be for agent hardening

Copy link
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Of course this is a mockup

| **3. Role-Based Access Control (RBAC)** | Assign least-privilege roles to team members within Netdata Cloud Rooms. | **High** |
| **4. Cloud Configuration Management** | Review change history for dashboards, alerts, and spaces. | **Medium** |
| **5. Alert Notification Security** | Secure all alert endpoints and notification channels. | **High** |
| **6. External Access Protection** | Secure the Cloud UI with SSO, enforce session expiration policies. | **Critical** |
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

The session expiration is something I have small issue with because cloud itself does not offer such setting. This needs to be fixed on SSO provider side.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Copy link
ContributorAuthor

@kanelatechnicalkanelatechnicalMay 7, 2025
edited
Loading

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

Let me know whether you think it's useful info for the hardening guide (I thought it was), I understand your pov but I think since this isn't the product page it's okay that it's there

@kanelatechnicalkanelatechnical marked this pull request as ready for reviewMay 12, 2025 09:21
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers

@M4iteeM4iteeM4itee left review comments

@AncaironAncaironAwaiting requested review from AncaironAncairon is a code owner

@ralphmralphmAwaiting requested review from ralphm

At least 1 approving review is required to merge this pull request.

Assignees
No one assigned
Labels
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

3 participants
@kanelatechnical@M4itee@ilyam8

[8]ページ先頭

©2009-2025 Movatter.jp