Deployment Security Guide

Zielgruppe: DevOps · IT-Infrastructure Status: Aktiv

Version: 1.0 Last Updated: February 2026


1. Purpose

This guide provides security requirements and best practices for deploying Nova IAM in production environments.

2. Pre-Deployment Checklist

Mandatory Security Configuration

# Item How Severity
1 Set SECRET_KEY SECRET_KEY=<random 64+ char string> in environment Critical
2 Change DB password Update DB_PASSWORD from default postgres Critical
3 Enable TLS Configure nginx with valid certificate or Let's Encrypt Critical
4 Restrict DB access Ensure PostgreSQL port is not exposed externally High
5 Set DB SSL mode Add DB_SSLMODE=require for remote database connections High
6 Secure .env file Verify .env is in .gitignore, set file permissions to 600 High
7 Rotate default credentials Change all default passwords for backend system connections High
8 Disable debug mode Ensure Flask is not running in debug mode (FLASK_DEBUG=0) Medium

Generating a Strong SECRET_KEY

# Linux/macOS
python3 -c "import secrets; print(secrets.token_hex(32))"

# Or using openssl
openssl rand -hex 32

3. Production Docker Deployment

services:
  app:
    image: nova-iam:latest
    environment:
      - SECRET_KEY=${SECRET_KEY}          # From .env, never hardcoded
      - DB_HOST=db
      - DB_PASSWORD=${DB_PASSWORD}
      - DB_SSLMODE=require
    networks:
      - backend
    restart: unless-stopped
    depends_on:
      db:
        condition: service_healthy

  db:
    image: postgres:16
    environment:
      - POSTGRES_PASSWORD=${DB_PASSWORD}
    volumes:
      - pgdata:/var/lib/postgresql/data
    networks:
      - backend                            # NOT exposed to frontend/internet
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U postgres"]
      interval: 10s
      timeout: 5s
      retries: 5

  nginx:
    image: nginx:alpine
    ports:
      - "443:443"
      - "80:80"                            # Redirect to HTTPS only
    networks:
      - frontend
      - backend
    volumes:
      - ./nginx.conf:/etc/nginx/conf.d/default.conf
      - ./certs:/etc/nginx/certs

networks:
  frontend:
  backend:
    internal: true                         # No external access

volumes:
  pgdata:

Key Points

  • Database is on an internal: true network (no internet access)
  • Only nginx ports (80, 443) are exposed
  • Application communicates with database over the isolated backend network
  • Health checks prevent the app from starting before the database is ready

4. TLS Configuration

Use the nginx-proxy + acme-companion pattern for automated certificate management:

  • Certificates auto-renew before expiration
  • Supports multiple domains
  • No manual certificate management required

Manual Certificate

If using manually obtained certificates:

  • Use TLS 1.2 or higher
  • Disable SSLv3, TLS 1.0, and TLS 1.1
  • Use strong cipher suites (ECDHE+AESGCM preferred)
  • Enable HSTS header: Strict-Transport-Security: max-age=31536000; includeSubDomains

5. Database Security

Connection Security

# Enable SSL for PostgreSQL connections
DB_SSLMODE=require

# For certificate-pinned connections
DB_SSLMODE=verify-full
DB_SSLROOTCERT=/path/to/ca-certificate.crt

Access Controls

  • Create a dedicated database user for Nova IAM (not postgres superuser)
  • Grant only necessary permissions: SELECT, INSERT, UPDATE, DELETE on application tables
  • Audit log table: grant only SELECT and INSERT (no UPDATE/DELETE)

Backup Strategy

  • Daily automated backups with pg_dump
  • Encrypt backups at rest using gpg or cloud provider encryption
  • Test restore procedures monthly
  • Store backups in a separate location from the database server

6. Network Security

Firewall Rules

Direction Port Protocol Source Purpose
Inbound 443 TCP Any HTTPS access
Inbound 80 TCP Any HTTP redirect to HTTPS
Outbound 443 TCP App Cloud AI API (if enabled)
Outbound 389/636 TCP App LDAP/LDAPS (if configured)
Outbound 443 TCP App Microsoft Graph API (if configured)
Outbound 3300+ TCP App SAP RFC (if configured)
  • Block all other inbound traffic
  • Rate limit login endpoint (e.g., 10 requests/minute per IP)
  • Consider a WAF (Web Application Firewall) in front of nginx

7. Monitoring & Alerting

Metric Alert Threshold Rationale
Failed login rate > 10/minute Brute force attempt
Audit log volume > 2x normal daily average Unusual activity
Database connections > 80% of max Resource exhaustion
Disk usage > 85% Prevent outage
Certificate expiry < 14 days Prevent TLS downtime
Application response time > 5 seconds (p95) Performance degradation

Log Aggregation

  • Forward Nova IAM audit logs to a SIEM (Splunk, ELK, Datadog)
  • Forward nginx access logs for traffic analysis
  • Forward PostgreSQL logs for database activity monitoring

8. Update & Patch Management

Application Updates

  1. Review release notes and changelog
  2. Test update in staging environment
  3. Back up database before production update
  4. Apply update during maintenance window
  5. Verify database migrations ran successfully
  6. Run smoke tests against production
  7. Monitor audit logs for anomalies post-update

Dependency Updates

  • Review and update Python dependencies quarterly
  • Monitor for CVEs in key dependencies (Flask, psycopg2, Werkzeug)
  • Use pip audit to scan for known vulnerabilities
Fragen zu diesem Dokument? Schreiben Sie an trust@nova-iam.com – wir bestätigen den Eingang innerhalb von 2 Werktagen.