Add security posture section (deliberate trade-offs + control-plane hardening)
This commit is contained in:
1 parent
0758a8fe6c
commit
afe89b62fa
1 file changed
+13
@@ -144,6 +144,19 @@ Privacy is a core value. Inference now runs through [Tinfoil](https://tinfoil.sh
|
||||
Because Tinfoil requires EHBP-encrypted request bodies (it rejects plaintext with `426 EHBP_REQUIRED`), the LiteLLM gateway routes through a local [Tinfoil proxy](https://github.com/tinfoilsh/tinfoil-proxy) sidecar, which verifies the enclave attestation and handles the encryption. LiteLLM talks plaintext OpenAI to the proxy; the proxy encrypts and forwards to the enclave.
|
||||
|
||||
|
||||
### Security posture
|
||||
|
||||
A plain-language summary of how the co-op's infrastructure is secured, and the trade-offs we've deliberately accepted.
|
||||
|
||||
- **Public-but-token-gated control plane.** The member portal (`portal.inference.coop`) is publicly reachable but every sensitive surface is gated: the admin endpoints require an `X-Admin-Token` header, the broker requires `X-Broker-Secret`, and the Open Collective webhook requires a secret token in its URL (Open Collective's webhooks aren't HMAC-signed, so a secret URL is the standard mechanism). All endpoints fail closed — unauthenticated requests get `401`. The portal stays public because the webhook is an external caller that can't go through Cloudron SSO.
|
||||
- **Secret separation.** Chat, broker, admin, and model-layer secrets are independent and independently rotatable, so a leak in one has bounded scope.
|
||||
- **Member isolation.** A member's API key is scoped to their own LiteLLM team and budget; the broker can only ever operate on the authenticated member's own keys.
|
||||
- **Rate limiting.** Control-plane endpoints (admin, broker, webhook, the model list) are rate-limited per IP. The member inference path is *not* rate-limited — it's capped by each member's budget instead, so legitimate long generations aren't throttled.
|
||||
- **No secrets in version control.** All credentials live in Cloudron environment variables, never in the repos.
|
||||
- **Accepted trade-off — keys at rest.** Member chat keys and API keys are stored in plaintext in the portal's database. This is functionally necessary (the injector needs the chat key per request; the broker must display a freshly-created API key once), and Cloudron app volumes aren't encrypted at rest. Access to that volume is limited to the portal app itself.
|
||||
- **Accepted trade-off — gateway surface.** The LiteLLM gateway must stay publicly reachable for member API access. Its admin UI and docs (`/docs`, `/redoc`, Swagger) are disabled; only the `/v1/*` API is exposed, which requires a bearer key.
|
||||
|
||||
|
||||
## Governance
|
||||
|
||||
Members govern the project through [Loomio](https://www.loomio.com) and the Open Collective. See the [Charter](charter.md) for the cooperative's values, membership terms, and governance structure, and [Open Questions](open-questions.md) for the decisions currently open for member discussion.
|
||||
|
||||
Reference in new issue
Block a user