Skip to content

Security: m3yyyyy/cloud-ops-observability-lab

Security

SECURITY.md

Security policy

Supported version

Security fixes are applied to the latest commit on main.

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature on the repository's Security tab. Include the affected route or component, reproduction steps, impact, and any suggested mitigation.

Deliberate safety boundaries

This repository is a local observability simulation, not a production monitoring agent.

  • It has no cloud credentials, shell execution, infrastructure mutation, or remediation endpoints.
  • Scenario selection is a stateless read-only query; unknown scenarios fail closed.
  • The API accepts JSON bodies up to 32 KB, disables the Express technology header, and returns generic internal-error responses.
  • Runbooks are bundled local JSON. No remote content is fetched or executed.
  • Runtime spans and logs are held in bounded process memory and disappear on restart.
  • The Docker Compose profile runs with a read-only filesystem and no-new-privileges.

Before connecting this project to real telemetry, add authentication, authorization, rate limiting, encrypted transport, retention controls, secret management, data redaction, and an approved threat model.

There aren't any published security advisories