Skip to content

Security ​

  • Sign-in: every API route needs a session, except creating the first administrator and signing in. Repeated failed sign-ins from the same address are locked out for a while.
  • The console's address: it is published with a Let's Encrypt certificate, and plain HTTP redirects to HTTPS. Orbit only answers requests that come through Traefik with a secret that changes every time Orbit starts, and the firewall keeps its port reachable only from the server and its workloads.
  • Agents: they need a client certificate from Orbit's own certificate authority that is not revoked or expired.
  • Added servers: their SSH host keys are pinned when you confirm the fingerprint, and every later connection refuses a different key. Pasted private keys live only in memory.
  • Secrets at rest: variables marked secret, database passwords and the GitHub App's key are sealed with AES-256-GCM, with a key kept outside Orbit's database. Passwords are hashed with Argon2id, and session and enrollment tokens are stored only as hashes. Orbit's data directory is readable only by root.
  • Logs: secrets and common credential patterns are redacted before anything is stored. See Running Orbit.
  • Releases: every release is signed. The console refuses to update from a release whose signature does not match the key pinned in the running Orbit.
  • Pull request previews: pull requests from forks never run on your servers.

Orbit by Cortex Labs