Deployment Security Guide
Version: 1.0 Last Updated: February 2026
1. Purpose
This guide provides security requirements and best practices for deploying Nova IAM in production environments.
2. Pre-Deployment Checklist
Mandatory Security Configuration
| # | Item | How | Severity |
|---|---|---|---|
| 1 | Set SECRET_KEY |
SECRET_KEY=<random 64+ char string> in environment |
Critical |
| 2 | Change DB password | Update DB_PASSWORD from default postgres |
Critical |
| 3 | Enable TLS | Configure nginx with valid certificate or Let's Encrypt | Critical |
| 4 | Restrict DB access | Ensure PostgreSQL port is not exposed externally | High |
| 5 | Set DB SSL mode | Add DB_SSLMODE=require for remote database connections |
High |
| 6 | Secure .env file |
Verify .env is in .gitignore, set file permissions to 600 |
High |
| 7 | Rotate default credentials | Change all default passwords for backend system connections | High |
| 8 | Disable debug mode | Ensure Flask is not running in debug mode (FLASK_DEBUG=0) |
Medium |
Generating a Strong SECRET_KEY
# Linux/macOS
python3 -c "import secrets; print(secrets.token_hex(32))"
# Or using openssl
openssl rand -hex 32
3. Production Docker Deployment
Recommended docker-compose.prod.yml Structure
services:
app:
image: nova-iam:latest
environment:
- SECRET_KEY=${SECRET_KEY} # From .env, never hardcoded
- DB_HOST=db
- DB_PASSWORD=${DB_PASSWORD}
- DB_SSLMODE=require
networks:
- backend
restart: unless-stopped
depends_on:
db:
condition: service_healthy
db:
image: postgres:16
environment:
- POSTGRES_PASSWORD=${DB_PASSWORD}
volumes:
- pgdata:/var/lib/postgresql/data
networks:
- backend # NOT exposed to frontend/internet
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres"]
interval: 10s
timeout: 5s
retries: 5
nginx:
image: nginx:alpine
ports:
- "443:443"
- "80:80" # Redirect to HTTPS only
networks:
- frontend
- backend
volumes:
- ./nginx.conf:/etc/nginx/conf.d/default.conf
- ./certs:/etc/nginx/certs
networks:
frontend:
backend:
internal: true # No external access
volumes:
pgdata:
Key Points
- Database is on an
internal: truenetwork (no internet access) - Only nginx ports (80, 443) are exposed
- Application communicates with database over the isolated backend network
- Health checks prevent the app from starting before the database is ready
4. TLS Configuration
Let's Encrypt (Recommended)
Use the nginx-proxy + acme-companion pattern for automated certificate management:
- Certificates auto-renew before expiration
- Supports multiple domains
- No manual certificate management required
Manual Certificate
If using manually obtained certificates:
- Use TLS 1.2 or higher
- Disable SSLv3, TLS 1.0, and TLS 1.1
- Use strong cipher suites (ECDHE+AESGCM preferred)
- Enable HSTS header:
Strict-Transport-Security: max-age=31536000; includeSubDomains
5. Database Security
Connection Security
# Enable SSL for PostgreSQL connections
DB_SSLMODE=require
# For certificate-pinned connections
DB_SSLMODE=verify-full
DB_SSLROOTCERT=/path/to/ca-certificate.crt
Access Controls
- Create a dedicated database user for Nova IAM (not
postgressuperuser) - Grant only necessary permissions:
SELECT,INSERT,UPDATE,DELETEon application tables - Audit log table: grant only
SELECTandINSERT(noUPDATE/DELETE)
Backup Strategy
- Daily automated backups with
pg_dump - Encrypt backups at rest using
gpgor cloud provider encryption - Test restore procedures monthly
- Store backups in a separate location from the database server
6. Network Security
Firewall Rules
| Direction | Port | Protocol | Source | Purpose |
|---|---|---|---|---|
| Inbound | 443 | TCP | Any | HTTPS access |
| Inbound | 80 | TCP | Any | HTTP redirect to HTTPS |
| Outbound | 443 | TCP | App | Cloud AI API (if enabled) |
| Outbound | 389/636 | TCP | App | LDAP/LDAPS (if configured) |
| Outbound | 443 | TCP | App | Microsoft Graph API (if configured) |
| Outbound | 3300+ | TCP | App | SAP RFC (if configured) |
Recommended Additional Rules
- Block all other inbound traffic
- Rate limit login endpoint (e.g., 10 requests/minute per IP)
- Consider a WAF (Web Application Firewall) in front of nginx
7. Monitoring & Alerting
Recommended Monitoring Points
| Metric | Alert Threshold | Rationale |
|---|---|---|
| Failed login rate | > 10/minute | Brute force attempt |
| Audit log volume | > 2x normal daily average | Unusual activity |
| Database connections | > 80% of max | Resource exhaustion |
| Disk usage | > 85% | Prevent outage |
| Certificate expiry | < 14 days | Prevent TLS downtime |
| Application response time | > 5 seconds (p95) | Performance degradation |
Log Aggregation
- Forward Nova IAM audit logs to a SIEM (Splunk, ELK, Datadog)
- Forward nginx access logs for traffic analysis
- Forward PostgreSQL logs for database activity monitoring
8. Update & Patch Management
Application Updates
- Review release notes and changelog
- Test update in staging environment
- Back up database before production update
- Apply update during maintenance window
- Verify database migrations ran successfully
- Run smoke tests against production
- Monitor audit logs for anomalies post-update
Dependency Updates
- Review and update Python dependencies quarterly
- Monitor for CVEs in key dependencies (Flask, psycopg2, Werkzeug)
- Use
pip auditto scan for known vulnerabilities
Fragen zu diesem Dokument? Schreiben Sie an
trust@nova-iam.com –
wir bestätigen den Eingang innerhalb von 2 Werktagen.