EKOSdocs
Docs / Operations Operate

Security

Threat model, controls and a hardening checklist.

Concern Control
Secrets in sources Built-in, non-disable-able redaction at every raw-content entry point; excluded files (.env, *.pem, id_rsa); [security] extends only
Irreversibility The ledger is append-only, so redaction is prevention. If something sensitive was indexed, the only removal is deleting .ekos/ and rebuilding
Agent access Read-only runtime; agents never touch source systems
Network exposure Loopback by default in docs; bearer token for TCP/HTTP; explicit --http-allow-origin
Writes over MCP Only ekos_identity_review and ekos_architecture_review, each appending a review event
Live queries ekos_clickhouse_query is off by default and executes a single validated SELECT
LLM providers Content sent to a provider leaves your machine — use ollama for fully local operation
Prompt injection Ledger text originated in your sources; treat it as data. Session-memory notes are returned inside an explicit untrusted envelope
Malformed MCP calls Unknown argument names are refused; numeric bounds are enforced; lines over 4 MB are rejected; a panicking tool call returns an error instead of taking the server down
MCP resource exhaustion At most 64 concurrent TCP connections; the HTTP transport queues at most 64 requests and answers 503 with Retry-After beyond that; traversals are capped and report truncated
Migration credentials Connections are aliases with a secret-env variable name; a DSN carrying a password is refused; loads read the source through a ClickHouse named collection, so no credential appears in a generated statement
Migration approvals Risk classes R0–R4 are computed, not declared; a requester cannot approve their own request; an approval covers only loads at or below its class and the exact artifacts it was granted on; there is no MCP approve
Web console If the session secret is unset or still the published placeholder, a random per-process secret replaces it
Local sandboxes The EKOS Migrate PostgreSQL and ClickHouse sandboxes (docker-compose.migrate.yml) publish their ports on 127.0.0.1 only
Dependencies scripts/audit.sh runs cargo audit over every Cargo workspace plus a lockfile-freshness check; the audit.yml workflow runs it on push, on pull requests and weekly, so a new advisory against unchanged code is still caught

Hardening checklist

  1. Run ekos as an unprivileged user; give the server read-only access to .ekos/.
  2. Use --token-file and TLS termination for any non-stdio transport.
  3. Keep provider keys out of ekos.toml and version control.
  4. Review ignore-patterns and [security] before the first build on a new estate.
  5. For EKOS Migrate, keep default-environment away from production, give approvers distinct identities, and run ekos migrate load --dry-run before the real load.
  6. Run scripts/audit.sh before a release.
  7. Report vulnerabilities per SECURITY.md in the repository.