Security
- Sign-in: every API route needs a session, except creating the first administrator and signing in. Repeated failed sign-ins from the same address are locked out for a while.
- The console's address: it is published with a Let's Encrypt certificate, and plain HTTP redirects to HTTPS. Orbit only answers requests that come through Traefik with a secret that changes every time Orbit starts, and the firewall keeps its port reachable only from the server and its workloads.
- Agents: they need a client certificate from Orbit's own certificate authority that is not revoked or expired.
- Added servers: their SSH host keys are pinned when you confirm the fingerprint, and every later connection refuses a different key. Pasted private keys live only in memory.
- Secrets at rest: variables marked secret, database passwords and the GitHub App's key are sealed with AES-256-GCM, with a key kept outside Orbit's database. Passwords are hashed with Argon2id, and session and enrollment tokens are stored only as hashes. Orbit's data directory is readable only by root.
- Logs: secrets and common credential patterns are redacted before anything is stored. See Running Orbit.
- Releases: every release is signed. The console refuses to update from a release whose signature does not match the key pinned in the running Orbit.
- Pull request previews: pull requests from forks never run on your servers.