Network and Security Boundaries
Network and Security Boundaries
Exact firewall rules, trusted source ranges, certificates, topology, and recovery procedures require restricted operator documentation.
Public-safe principles
Expose only required services
Separate admin, customer portal, provisioning, database, and monitoring networks where appropriate
Use TLS with managed certificates
Keep SELinux/firewalld enabled and configure required policy explicitly
Use least-privilege service accounts and sudo rules
Keep secrets in protected environment/secret stores
Package-provided service definitions under Install/files/ are the source for shipped ports/services; review them with current security policy.