deploy: require redis auth (--requirepass) across all consumers

Redis without a password was the root cause of the security incident
(cron miner via unauthenticated replication RCE, see
.forcc/deploy/SESSION2-FINDINGS.md). Loopback binding alone doesn't
protect against a compromised container inside the same compose
network, so wire REDIS_PASSWORD as a required secret everywhere redis
is used: backend/worker/worker-transcriber(-gpu), redis-exporter,
livekit and egress (via rendered templates). docker compose now
refuses to start without it instead of silently running unauthenticated.
This commit is contained in:
2026-07-25 22:59:34 +03:00
parent d593add0f3
commit 5e42f6d11b
9 changed files with 77 additions and 15 deletions

1
.gitignore vendored
View File

@@ -39,6 +39,7 @@ deploy/**/*.local.yml
# содержат реальные секреты/IP, рендерятся перед `docker compose up`.
deploy/coturn/turnserver.conf
deploy/livekit/livekit.yaml
deploy/egress/egress.yaml
# Артефакты Celery beat
celerybeat-schedule*.db