Docs / Operations Operate
Security
Threat model, controls and a hardening checklist.
| Concern | Control |
|---|---|
| Secrets in sources | Built-in, non-disable-able redaction at every raw-content entry point; excluded files (.env, *.pem, id_rsa); [security] extends only |
| Irreversibility | The ledger is append-only, so redaction is prevention. If something sensitive was indexed, the only removal is deleting .ekos/ and rebuilding |
| Agent access | Read-only runtime; agents never touch source systems |
| Network exposure | Loopback by default in docs; bearer token for TCP/HTTP; explicit --http-allow-origin |
| Writes over MCP | Only ekos_identity_review and ekos_architecture_review, each appending a review event |
| Live queries | ekos_clickhouse_query is off by default and executes a single validated SELECT |
| LLM providers | Content sent to a provider leaves your machine — use ollama for fully local operation |
| Prompt injection | Ledger text originated in your sources; treat it as data. Session-memory notes are returned inside an explicit untrusted envelope |
| Malformed MCP calls | Unknown argument names are refused; numeric bounds are enforced; lines over 4 MB are rejected; a panicking tool call returns an error instead of taking the server down |
| MCP resource exhaustion | At most 64 concurrent TCP connections; the HTTP transport queues at most 64 requests and answers 503 with Retry-After beyond that; traversals are capped and report truncated |
| Migration credentials | Connections are aliases with a secret-env variable name; a DSN carrying a password is refused; loads read the source through a ClickHouse named collection, so no credential appears in a generated statement |
| Migration approvals | Risk classes R0–R4 are computed, not declared; a requester cannot approve their own request; an approval covers only loads at or below its class and the exact artifacts it was granted on; there is no MCP approve |
| Web console | If the session secret is unset or still the published placeholder, a random per-process secret replaces it |
| Local sandboxes | The EKOS Migrate PostgreSQL and ClickHouse sandboxes (docker-compose.migrate.yml) publish their ports on 127.0.0.1 only |
| Dependencies | scripts/audit.sh runs cargo audit over every Cargo workspace plus a lockfile-freshness check; the audit.yml workflow runs it on push, on pull requests and weekly, so a new advisory against unchanged code is still caught |
Hardening checklist
- Run
ekosas an unprivileged user; give the server read-only access to.ekos/. - Use
--token-fileand TLS termination for any non-stdio transport. - Keep provider keys out of
ekos.tomland version control. - Review
ignore-patternsand[security]before the firstbuildon a new estate. - For EKOS Migrate, keep
default-environmentaway from production, give approvers distinct identities, and runekos migrate load --dry-runbefore the real load. - Run
scripts/audit.shbefore a release. - Report vulnerabilities per
SECURITY.mdin the repository.