Operations

Security

Hardening checklist for a private or public instance.

Before opening network access

  • Replace NASDASH_ADMIN_PASSWORD, NASDASH_VIEWER_PASSWORD, and NASDASH_JWT_SECRET;
  • Keep secrets out of version-controlled Compose files;
  • Enable HTTPS or a private VPN;
  • Do not expose the Docker proxy to the internet;
  • Limit Proxmox and Tailscale permissions to the necessary read access;
  • Verify visibility using a read-only account;
  • Back up /app/data and test a restoration;
  • Regularly update the image.

The official container runs the application with the UID/GID 1001. When using a bind mount, grant this user access to the directory without making it globally writable.

Sensitive data

Integration tokens are masked in standard responses and encrypted in persistent configuration. Encryption continuity depends on the keys stored in /app/data and your stable secrets: back up the entire directory, not just config.json.

Reporting a vulnerability

Do not open a public ticket containing an unpatched vulnerability, a private IP address, or a secret. Follow the security policy for contributors.