updated playbook with more information to check
This commit is contained in:
1 parent
f9b50d7e81
commit
efda4182b1
1 file changed
+19
@@ -155,10 +155,29 @@ Report all FAIL/WARN findings. Do not proceed to go-live recommendation until cr
|
|||||||
- [ ] No abandoned or unmaintained packages with known issues
|
- [ ] No abandoned or unmaintained packages with known issues
|
||||||
- [ ] Docker base images are from official/verified sources
|
- [ ] Docker base images are from official/verified sources
|
||||||
|
|
||||||
|
### 3i. Request & Session Hardening
|
||||||
|
- [ ] Session/auth cookies set `Secure`, `HttpOnly`, and `SameSite=Strict` or `Lax`
|
||||||
|
- [ ] CSRF protection is in place for state-changing (non-GET) endpoints, or the API is stateless/token-authenticated (not cookie-authenticated) and doesn't need it
|
||||||
|
- [ ] CORS policy restricts `Access-Control-Allow-Origin` to known origins — no wildcard `*` combined with `Access-Control-Allow-Credentials: true`
|
||||||
|
- [ ] File uploads enforce a max size limit and restrict allowed file types/extensions
|
||||||
|
|
||||||
|
### 3j. Backups & Recovery
|
||||||
|
- [ ] Database/data volumes have an automated backup process (cron, script, or handled by the DB image)
|
||||||
|
- [ ] Backups are stored outside the container (separate volume, external disk, or remote target) so they survive the container/host being wiped
|
||||||
|
- [ ] A restore from backup has been tested at least once, not just assumed to work
|
||||||
|
- [ ] Backup files containing sensitive data are encrypted or access-restricted
|
||||||
|
|
||||||
|
### 3k. Logging & Observability
|
||||||
|
- [ ] Logs are rotated or size-capped (Docker `logging.driver`/`max-size`, or app-level rotation) so they can't fill disk over time
|
||||||
|
- [ ] Logs persist outside the container (volume-mounted or shipped elsewhere) so they survive a container restart/crash
|
||||||
|
- [ ] The app trusts `X-Forwarded-For`/`X-Real-IP` from the proxy correctly, so rate limiting and audit logs record the real client IP, not NPM's
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Section 4: Go-Live Decision
|
## Section 4: Go-Live Decision
|
||||||
|
|
||||||
|
- [ ] Is a rollback or "what to do if this breaks/is compromised" step documented (README or runbook) for this service?
|
||||||
|
|
||||||
After all sections are complete:
|
After all sections are complete:
|
||||||
|
|
||||||
- List all unresolved FINDs grouped by severity: **CRITICAL / HIGH / MEDIUM / LOW**
|
- List all unresolved FINDs grouped by severity: **CRITICAL / HIGH / MEDIUM / LOW**
|
||||||
|
|||||||
Reference in new issue
Block a user