sitescope a small health monitor and status page for a few hosts

Reference

Security model

What sitescope protects, from whom, and how. A monitor sees everything, so it is built to be uninteresting to break into.

What it holds

Rules it follows

Nothing it does changes the infrastructure. Tokens are scoped read only, probes only ask, and the open-relay probe stops at RCPT TO.

Process hardening

measure effect
mlock + MADV_DONTDUMP on the vault buffer secrets aren’t swapped out or written to crash dumps
PR_SET_DUMPABLE=0 no ptrace or /proc/PID/mem from same-user processes
LimitCORE=0, RLIMIT_CORE=0 no core files
buffers zeroed on lock, SIGTERM and exit a locked hub holds no plaintext
separate users for hub and agent the vault process has no capabilities
systemd sandboxing see NixOS module

Authentication

Known limits