Pulse/cmd/pulse-sensor-proxy
rcourtman 524f42cc28 security: complete Phase 1 sensor proxy hardening
Implements comprehensive security hardening for pulse-sensor-proxy:
- Privilege drop from root to unprivileged user (UID 995)
- Hash-chained tamper-evident audit logging with remote forwarding
- Per-UID rate limiting (0.2 QPS, burst 2) with concurrency caps
- Enhanced command validation with 10+ attack pattern tests
- Fuzz testing (7M+ executions, 0 crashes)
- SSH hardening, AppArmor/seccomp profiles, operational runbooks

All 27 Phase 1 tasks complete. Ready for production deployment.
2025-10-20 15:13:37 +00:00
..
audit.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
audit_test.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
auth.go Automate sensor proxy container mount and auth 2025-10-14 12:41:48 +00:00
auth_test.go Automate sensor proxy container mount and auth 2025-10-14 12:41:48 +00:00
cleanup.go feat: add comprehensive node cleanup system 2025-10-17 18:53:45 +00:00
config.go Automate sensor proxy container mount and auth 2025-10-14 12:41:48 +00:00
main.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
main_test.go test: add comprehensive security tests and documentation 2025-10-19 16:47:13 +00:00
metrics.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
ssh.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
ssh_test.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
throttle.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
throttle_test.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
validation.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
validation_fuzz_test.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00
validation_test.go security: complete Phase 1 sensor proxy hardening 2025-10-20 15:13:37 +00:00