Platform security

Explicit trust boundaries from identity to upstream connections.

This page describes controls present in the source project and their boundaries. It makes no certification or independent-assurance claim.

Authentication

Built-in sign-in, automatic first administrator, LDAP, Google, and generic OIDC flows.

Roles & Groups

Six fixed platform roles, local and LDAP groups, and LDAP membership mapping at sign-in.

Access Policy

User/group/anonymous subjects, organization/project/repository scope, name/key matching, exclusions, and label ALL/ANY rules.

API Tokens

Scoped permissions and a separate token lifecycle for automation.

Audit & Logs

Durable audit, package-usage, operation, outbound, and application-log records.

Proxy Security

TLS validation, SSRF protection, redirect inspection, system proxy, and write-only upstream-secret handling.

Architecture

Where controls apply

Anonymous access

Restricted to read-only proxy repository flows and gated by the Anonymous account being enabled.

Upstream connections

Basic, bearer, and selected format-specific header/token credentials are supported; secret values are never returned by read APIs.

Data layer

Metadata and audit records live in PostgreSQL; artifact content lives in the selected filesystem or S3-compatible storage component.

Network egress

System-proxy and repository-proxy settings provide controlled egress. No public, verified air-gapped operating profile is published.

No public certification, independent penetration-test summary, assurance report, or SLA document is currently published.

Technical evaluation

Evaluate your package flow on Smart Kubaba.

Let’s review your formats, deployment, and security policies together.