Originally created by: pyy3
Severity: Medium (doc-vs-reality mismatch) · Type: documentation / security
docs/security-architecture.md describes a stronger network posture than the shipped configuration enforces. Operators who trust the doc may deploy assuming isolation that is not actually configured.
docs/security-architecture.md states (paraphrased):
But docker-compose.yml publishes ClickHouse ports 8123/9000/15432 to the host, .env.example ships weak default credentials, and profiles.yml uses secure: false.
The documented security model and the default deployment disagree. This is a classic "trusted the doc, got breached" gap.
Either:
127.0.0.1, proxy-only access, TLS), orAlso add a short section covering Airbyte connector security (credential storage, OAuth app registration), which the doc currently omits.
Originally posted by: pyy3
Fixed in [#34] (merged to
main).Related
Tickets:
#34Ticket changed by: pyy3