Skip to content
This repository has been archived by the owner on Apr 17, 2019. It is now read-only.

Documentation for Iroha installation security tips #2129

Merged
merged 4 commits into from
Mar 11, 2019

Conversation

baydarich
Copy link
Contributor

Description of the Change

Added tips to Read the Docs for securing Iroha installation ranging from physical security to logging. The guide itself is more general and aimed at meeting obvious yet necessary requirements.

Benefits

The guide helps administrators to avoid possible security problems that are not directly related to Iroha.

Possible Drawbacks

None

@sudomann
Copy link

sudomann commented Feb 28, 2019

@baydarich I recently created a pull request regarding deploying ansible in kubernetes clusters. I have no experience in security of any sort; could you make some suggestions as to how i could improve security handling?
Best I have thought of is the generated files containing private keys to be deleted by ansible after being used to deploy.

docs/source/guides/sec-install.rst Outdated Show resolved Hide resolved
^^^^^^^^^^^^^^^^^^^^^^
- Collect and ship logs to a dedicated machine using an agent (e.g., Filebeat).
- Collect logs from all Iroha peers in a central point (e.g., Logstash).
- Enable docker healthcheck.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right now we do not have a mechanism to identify the health of a running container. There are custom implementations that use gRPC to test if Iroha is ready to accept connections (e.g., https://github.com/d3ledger/notary/blob/7b1796472538c33817ebfea67f436221285ebc7d/docker/grpc-healthcheck.dockerfile) but this is not very reliable indicator.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done - healthcheck mentioning is deleted.

@baydarich
Copy link
Contributor Author

@sudomann I left a comment in your pull request

@neewy neewy added this to the rc5 milestone Mar 11, 2019

Updates
^^^^^^^
Install latest operating system security patches and update it regularly.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the latest

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants