Skip to content

fix: harden private tracker deployment - #24

Merged
DeepZone merged 1 commit into
mainfrom
fix/tracker-deployment-hardening
Aug 21, 2026
Merged

fix: harden private tracker deployment#24
DeepZone merged 1 commit into
mainfrom
fix/tracker-deployment-hardening

Conversation

@DeepZone

Copy link
Copy Markdown
Owner

Summary

  • make the telemetry API host binding configurable for a reverse proxy on another private host
  • document safe host-side secret permissions for distinct unprivileged container users
  • ignore macOS AppleDouble metadata in tracker builds and migration discovery
  • execute migration statements individually for broader PostgreSQL protocol compatibility

Verification

  • tracker unit tests pass
  • deployed on 192.168.58.161 with tracker and PostgreSQL healthy
  • public health endpoint returns 200
  • public listener rejects dashboard routes with 404
  • dashboard requires authentication and valid login returns 200
  • PostgreSQL remains unpublished

@DeepZone
DeepZone marked this pull request as ready for review August 21, 2026 13:28
@DeepZone
DeepZone merged commit 6dbfa7d into main Aug 21, 2026
12 checks passed
@DeepZone
DeepZone deleted the fix/tracker-deployment-hardening branch August 21, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant