#227: hardening guide / VS-NfD reference configuration #275

Closed
fable-5 wants to merge 3 commits from issue-227-hardening-guide into main
Collaborator

Adds docs/vs-nfd/50-haertungsleitfaden.md: complete reference profile (instance + deploy level) with exact names, values and reasons; auth.local row pending #216 with stated compensation; verification checklist; binding same-PR update rule; cross-refs to #226/#230 docs. Stacked on #274.

Adds docs/vs-nfd/50-haertungsleitfaden.md: complete reference profile (instance + deploy level) with exact names, values and reasons; auth.local row pending #216 with stated compensation; verification checklist; binding same-PR update rule; cross-refs to #226/#230 docs. Stacked on #274.
fable-5 added 3 commits 2026-07-31 09:59:29 +02:00
#228: security documentation (architecture, data flows, network plan)
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m26s
CI / Build container images (pull_request) Successful in 13s
CI / Auth e2e pack (pull_request) Successful in 9m27s
CI / Import/export fidelity gate (pull_request) Failing after 13s
1cf0458593
docs/vs-nfd/60-sicherheitsdokumentation.md: component diagram with per-
service purpose and privileges, network plan digit-exact against the
deploy compose (127.0.0.1-only app bindings, internal-only data zone),
data-flow diagrams (auth, realtime editing incl. LISTEN/NOTIFY and the
60s collab token, export via the pinned sidecars, backup incl. the
ADR-0026 allowlist, and every read channel), named trust boundaries
(reverse proxy, plugin sandbox, outbound SMTP/mirror), and the complete
list of content copies — in-database, on-volume and outside the
instance — that the deletion concept in #229 builds on. Mermaid only,
German (assessor audience), with the maintained-in-same-PR rule stated.

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
#229: operations manual (install, update, backup/restore, deletion, roles)
All checks were successful
CI / Lint, typecheck, test (pull_request) Successful in 6m33s
CI / Build container images (pull_request) Successful in 15s
CI / Auth e2e pack (pull_request) Successful in 9m20s
CI / Import/export fidelity gate (pull_request) Successful in 1m7s
d641c5dc8a
docs/vs-nfd/70-betriebshandbuch.md: installation as run on the real
stages (airgap variant explicitly pending #218-#221 with what already
exists as groundwork), update/rollback incl. the no-down-migrations
caveat, backup/restore with the ADR-0026 target allowlist and the
rehearsed monthly restore drill (evidence: logs on #98), the full
scheduler-job table (cadences verified against code), the deletion-and-
destruction chapter built on the #228 copy list (per content type:
what deletion reaches, what remains, immediate-destruction path,
decommissioning), and role separation incl. the deliberate limits of a
Site Admin and the honest note that Site Admin read-bypass makes the
content/platform split non-absolute app-side. Every procedure carries
its evidence level (erprobt / nicht geprobt / offen) — nothing claimed
above what was actually executed.

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
#227: hardening guide with the VS-NfD reference configuration
Some checks failed
CI / Lint, typecheck, test (pull_request) Failing after 15s
CI / Auth e2e pack (pull_request) Has been skipped
CI / Import/export fidelity gate (pull_request) Has been skipped
CI / Build container images (pull_request) Has been skipped
0dc9789cb1
docs/vs-nfd/50-haertungsleitfaden.md: one adoptable profile — every
entry with the exact switch name, value, default and the reason, split
into instance settings (registration closed, api/mcp off, feeds off,
plugins off, classification defaults vs_nfd + upload block, svg reject,
minimal extension list) and deploy-level configuration (empty
BACKUP_ALLOWED_TARGETS enforces backup-local-only outside Site-Admin
reach; tightened session hours; SMTP deliberately unconfigured with the
consequence stated honestly). auth.local.enabled is listed as the one
pending row (#216) with its compensation until then; the guide states
the binding updated-in-same-PR rule for every future switch. Includes
an operator verification checklist (four unauthenticated 404 curls +
readyz + admin spot checks). Cross-referenced from the delimitation
statement (file names made concrete) and consumed by the Grundschutz
mapping (#230).

Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
Author
Collaborator

Landed on main via the fast-forward chain: this branch commit (0dc9789) is contained verbatim in the green stacked runs of PRs #276 (CI 575/576) and #277 (CI 577/578); this PR's own run 574 failed in the Set up Node.js action (documented runner action-cache infra signature under parallel starts, not a tree failure). Closing; the commit is on main.

Landed on main via the fast-forward chain: this branch commit (0dc9789) is contained verbatim in the green stacked runs of PRs #276 (CI 575/576) and #277 (CI 577/578); this PR's own run 574 failed in the Set up Node.js action (documented runner action-cache infra signature under parallel starts, not a tree failure). Closing; the commit is on main.
fable-5 closed this pull request 2026-07-31 10:34:19 +02:00
Author
Collaborator

Correction to the note above: at the time of closing, the commit was NOT yet on main - the whole M30 chain first had to be rebased onto the M26 head (the branches were cut before the last three M26 merges were fetched, so fast-forward was impossible; every merge attempt answered 500 DivergingFastForwardOnly). The rebased commit 2c6eff8 landed on main via the green chain (runs 579-582, merges of #273/#274/#276/#277). Content unchanged.

Correction to the note above: at the time of closing, the commit was NOT yet on main - the whole M30 chain first had to be rebased onto the M26 head (the branches were cut before the last three M26 merges were fetched, so fast-forward was impossible; every merge attempt answered 500 DivergingFastForwardOnly). The rebased commit 2c6eff8 landed on main via the green chain (runs 579-582, merges of #273/#274/#276/#277). Content unchanged.
Some checks failed
CI / Lint, typecheck, test (pull_request) Failing after 15s
Required
Details
CI / Auth e2e pack (pull_request) Has been skipped
CI / Import/export fidelity gate (pull_request) Has been skipped
CI / Build container images (pull_request) Has been skipped
Required
Details

Pull request closed

Sign in to join this conversation.
No description provided.