rcourtman
524f42cc28
security: complete Phase 1 sensor proxy hardening
Implements comprehensive security hardening for pulse-sensor-proxy:
- Privilege drop from root to unprivileged user (UID 995)
- Hash-chained tamper-evident audit logging with remote forwarding
- Per-UID rate limiting (0.2 QPS, burst 2) with concurrency caps
- Enhanced command validation with 10+ attack pattern tests
- Fuzz testing (7M+ executions, 0 crashes)
- SSH hardening, AppArmor/seccomp profiles, operational runbooks
All 27 Phase 1 tasks complete. Ready for production deployment.
2025-10-20 15:13:37 +00:00
..
2025-10-14 09:45:32 +00:00
2025-10-11 23:29:47 +00:00
2025-10-20 15:13:37 +00:00
2025-10-20 15:13:37 +00:00
2025-10-16 08:15:49 +00:00
2025-10-18 13:06:41 +00:00
2025-10-14 15:47:49 +00:00
2025-10-15 22:25:04 +00:00
2025-10-14 15:47:49 +00:00
2025-10-14 15:47:49 +00:00
2025-10-11 23:29:47 +00:00
2025-10-18 11:50:57 +00:00
2025-10-18 11:50:57 +00:00
2025-10-11 23:29:47 +00:00
2025-10-11 23:29:47 +00:00
2025-10-20 15:13:37 +00:00
2025-10-16 08:15:49 +00:00
2025-10-14 15:47:49 +00:00
2025-10-16 08:15:49 +00:00
2025-10-18 11:50:57 +00:00
2025-10-16 08:15:49 +00:00
2025-10-11 23:29:47 +00:00
2025-10-16 08:15:49 +00:00
2025-10-19 16:47:13 +00:00
2025-10-18 07:34:18 +00:00
2025-10-16 08:15:49 +00:00
2025-10-14 16:13:53 +00:00
2025-10-15 19:27:19 +00:00
2025-10-16 08:15:49 +00:00