Repository navigation
Security
Actionbot edited this page Oct 5, 2026
·
7 revisions
ShieldPM provides a layered security architecture that protects your services at multiple levels — from network to application layer.
┌──────────┐ ┌──────────────────────────────────────────────────┐
│ Client │────▶│ ShieldPM │
└──────────┘ │ │
│ Layer 1: Network │
│ ┌────────────┐ ┌────────────┐ ┌───────────┐ │
│ │ Rate Limit │ │ IP Access │ │ mTLS │ │
│ │ (429) │ │ Lists │ │ Client │ │
│ └─────┬──────┘ └─────┬──────┘ └─────┬─────┘ │
│ ▼ ▼ ▼ │
│ Layer 2: Authentication │
│ ┌────────────┐ ┌────────────┐ │
│ │ Basic Auth │ │ OAuth2 / │ │
│ │ │ │ SSO │ │
│ └─────┬──────┘ └─────┬──────┘ │
│ ▼ ▼ │
│ Layer 3: Application Firewall │
│ ┌────────────┐ ┌────────────┐ ┌───────────┐ │
│ │ ModSec │ │ OpenAppSec │ │ Anubis │ │
│ │ (CRS WAF) │ │ (AI WAF) │ │ (AI FW) │ │
│ └─────┬──────┘ └─────┬──────┘ └─────┬─────┘ │
│ ▼ ▼ ▼ │
│ Layer 4: Threat Intelligence │
│ ┌────────────────────────────────────────────┐ │
│ │ CrowdSec (IPS) │ │
│ │ Community-driven IP Reputation │ │
│ └────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────┘
│
▼
┌──────────────────┐
│ Your Backend │
│ (Protected) │
└──────────────────┘
| Feature | Type | Protection Against | Configuration |
|---|---|---|---|
| CrowdSec | IPS | Brute force, botnets, known malicious IPs | Sidecar / System service |
| ModSecurity | WAF | SQL injection, XSS, path traversal | Per-host toggle |
| OpenAppSec | AI WAF | Zero-day attacks, unknown patterns | Module + Agent |
| Anubis | Bot challenge | AI crawlers, automated bots, scrapers | Per-host rules; optional ANUBIS_ENABLED
|
| Access Lists | ACL | Unauthorized access | Per-host assignment |
| IP Firewall | IP policy | Operator-selected networks and countries | Central lists; per-host rules and exceptions |
| OAuth2-Proxy | SSO | Unauthorized access via Identity Provider | Per-host assignment |
| Rate Limiting | DDoS | Abuse, scraping, brute force | Per-host config |
| mTLS | Zero Trust | All unauthorized clients | Access List + Internal CA |
| Block Exploits | Basic Rules | Common attack patterns | Per-host toggle |
| HSTS | Header | Protocol downgrade attacks | Per-host / global |
ShieldPM supports modern TLS protocols out of the box:
| Protocol | Status | Notes |
|---|---|---|
| TLS 1.3 | ✅ Default | Fastest, most secure |
| TLS 1.2 | ✅ Supported | For older client compatibility |
| HTTP/3 (QUIC) | ✅ When enabled | Requires UDP listener and DISABLE_H3_QUIC=false
|
| ML-KEM-768 | Conditional | Hybrid key exchange depends on the Nginx/OpenSSL build and client support; internal CA signatures remain ECDSA |
| Method | Best For | Automation |
|---|---|---|
| Let's Encrypt | Public-facing services | ✅ Auto-renew |
| DNS Challenge | Wildcards, blocked port 80 | ✅ Auto-renew |
| Custom Cert | Corporate CAs, bought certs | ❌ Manual |
| Internal CA | Private/internal services | ✅ Auto-issue |
👉 SSL Certificates Guide | Internal PKI Guide
- Admin UI not publicly accessible (use tunnel/VPN or Access List)
- HSTS enabled on production hosts
- Block Exploits enabled on all Proxy Hosts
- CrowdSec installed and configured
- ModSecurity enabled on sensitive hosts (login pages, APIs)
- Rate Limiting configured on authentication endpoints
- Dead Host (
*.yourdomain.com) catching undefined subdomains - SSL certificates configured for all public hosts
- HTTP/3 enabled (UDP 443 open)
- Regular backups via GitOps or manual
tar
Warning
Use a private, access-controlled repository for GitOps. The current export serializes configuration fields such as DDNS provider credentials, Cloudflared tunnel tokens, and Access List metadata to YAML. Review repository access and rotate exposed credentials if such an export has ever been pushed to a public remote. GitOps does not replace a full backup of private certificate keys or the database.