deploy: require redis auth (--requirepass) across all consumers
Redis without a password was the root cause of the security incident (cron miner via unauthenticated replication RCE, see .forcc/deploy/SESSION2-FINDINGS.md). Loopback binding alone doesn't protect against a compromised container inside the same compose network, so wire REDIS_PASSWORD as a required secret everywhere redis is used: backend/worker/worker-transcriber(-gpu), redis-exporter, livekit and egress (via rendered templates). docker compose now refuses to start without it instead of silently running unauthenticated.
This commit is contained in:
1
.gitignore
vendored
1
.gitignore
vendored
@@ -39,6 +39,7 @@ deploy/**/*.local.yml
|
||||
# содержат реальные секреты/IP, рендерятся перед `docker compose up`.
|
||||
deploy/coturn/turnserver.conf
|
||||
deploy/livekit/livekit.yaml
|
||||
deploy/egress/egress.yaml
|
||||
|
||||
# Артефакты Celery beat
|
||||
celerybeat-schedule*.db
|
||||
|
||||
Reference in New Issue
Block a user