Operations
Security
Hardening checklist for a private or public instance.
Before opening network access
- Replace
NASDASH_ADMIN_PASSWORD,NASDASH_VIEWER_PASSWORD, andNASDASH_JWT_SECRET; - Keep secrets out of version-controlled Compose files;
- Enable HTTPS or a private VPN;
- Do not expose the Docker proxy to the internet;
- Limit Proxmox and Tailscale permissions to the necessary read access;
- Verify visibility using a read-only account;
- Back up
/app/dataand test a restoration; - Regularly update the image.
The official container runs the application with the UID/GID 1001. When using a bind mount, grant this user access to the directory without making it globally writable.
Sensitive data
Integration tokens are masked in standard responses and encrypted in persistent configuration. Encryption continuity depends on the keys stored in /app/data and your stable secrets: back up the entire directory, not just config.json.
Reporting a vulnerability
Do not open a public ticket containing an unpatched vulnerability, a private IP address, or a secret. Follow the security policy for contributors.