Skip to content

Security

Actionbot edited this page Oct 5, 2026 · 7 revisions

Security Overview

ShieldPM provides a layered security architecture that protects your services at multiple levels — from network to application layer.


🏗️ Security Layers

  ┌──────────┐     ┌──────────────────────────────────────────────────┐
  │  Client   │────▶│                    ShieldPM                      │
  └──────────┘     │                                                  │
                   │  Layer 1: Network                                │
                   │  ┌────────────┐  ┌────────────┐  ┌───────────┐  │
                   │  │ Rate Limit │  │ IP Access  │  │  mTLS     │  │
                   │  │ (429)      │  │ Lists      │  │  Client   │  │
                   │  └─────┬──────┘  └─────┬──────┘  └─────┬─────┘  │
                   │        ▼               ▼               ▼        │
                   │  Layer 2: Authentication                         │
                   │  ┌────────────┐  ┌────────────┐                 │
                   │  │ Basic Auth │  │  OAuth2 /  │                 │
                   │  │            │  │  SSO       │                 │
                   │  └─────┬──────┘  └─────┬──────┘                 │
                   │        ▼               ▼                        │
                   │  Layer 3: Application Firewall                   │
                   │  ┌────────────┐  ┌────────────┐  ┌───────────┐  │
                   │  │ ModSec     │  │ OpenAppSec │  │  Anubis   │  │
                   │  │ (CRS WAF)  │  │ (AI WAF)   │  │ (AI FW)   │  │
                   │  └─────┬──────┘  └─────┬──────┘  └─────┬─────┘  │
                   │        ▼               ▼               ▼        │
                   │  Layer 4: Threat Intelligence                    │
                   │  ┌────────────────────────────────────────────┐  │
                   │  │           CrowdSec (IPS)                   │  │
                   │  │     Community-driven IP Reputation          │  │
                   │  └────────────────────────────────────────────┘  │
                   └──────────────────────────────────────────────────┘
                                        │
                                        ▼
                              ┌──────────────────┐
                              │   Your Backend    │
                              │   (Protected)     │
                              └──────────────────┘

🛡️ Feature Comparison

Feature Type Protection Against Configuration
CrowdSec IPS Brute force, botnets, known malicious IPs Sidecar / System service
ModSecurity WAF SQL injection, XSS, path traversal Per-host toggle
OpenAppSec AI WAF Zero-day attacks, unknown patterns Module + Agent
Anubis Bot challenge AI crawlers, automated bots, scrapers Per-host rules; optional ANUBIS_ENABLED
Access Lists ACL Unauthorized access Per-host assignment
IP Firewall IP policy Operator-selected networks and countries Central lists; per-host rules and exceptions
OAuth2-Proxy SSO Unauthorized access via Identity Provider Per-host assignment
Rate Limiting DDoS Abuse, scraping, brute force Per-host config
mTLS Zero Trust All unauthorized clients Access List + Internal CA
Block Exploits Basic Rules Common attack patterns Per-host toggle
HSTS Header Protocol downgrade attacks Per-host / global

🔐 Encryption

TLS Protocols

ShieldPM supports modern TLS protocols out of the box:

Protocol Status Notes
TLS 1.3 ✅ Default Fastest, most secure
TLS 1.2 ✅ Supported For older client compatibility
HTTP/3 (QUIC) ✅ When enabled Requires UDP listener and DISABLE_H3_QUIC=false
ML-KEM-768 Conditional Hybrid key exchange depends on the Nginx/OpenSSL build and client support; internal CA signatures remain ECDSA

Certificate Management

Method Best For Automation
Let's Encrypt Public-facing services ✅ Auto-renew
DNS Challenge Wildcards, blocked port 80 ✅ Auto-renew
Custom Cert Corporate CAs, bought certs ❌ Manual
Internal CA Private/internal services ✅ Auto-issue

👉 SSL Certificates Guide | Internal PKI Guide


📋 Security Hardening Checklist

  • Admin UI not publicly accessible (use tunnel/VPN or Access List)
  • HSTS enabled on production hosts
  • Block Exploits enabled on all Proxy Hosts
  • CrowdSec installed and configured
  • ModSecurity enabled on sensitive hosts (login pages, APIs)
  • Rate Limiting configured on authentication endpoints
  • Dead Host (*.yourdomain.com) catching undefined subdomains
  • SSL certificates configured for all public hosts
  • HTTP/3 enabled (UDP 443 open)
  • Regular backups via GitOps or manual tar

Warning

Use a private, access-controlled repository for GitOps. The current export serializes configuration fields such as DDNS provider credentials, Cloudflared tunnel tokens, and Access List metadata to YAML. Review repository access and rotate exposed credentials if such an export has ever been pushed to a public remote. GitOps does not replace a full backup of private certificate keys or the database.


🏠 Home | 🔒 SSL Certificates | 🐞 Report a Bug

Clone this wiki locally