Menu ▾ ▴

#25 [Security/Docs] security-architecture.md overstates ClickHouse network isolation

closed
nobody
None
2026-06-13
2026-06-12
Anonymous
No

Originally created by: pyy3

Severity: Medium (doc-vs-reality mismatch) · Type: documentation / security

Summary

docs/security-architecture.md describes a stronger network posture than the shipped configuration enforces. Operators who trust the doc may deploy assuming isolation that is not actually configured.

Location

docs/security-architecture.md states (paraphrased):

  • "ClickHouse isolation — private network only, no public endpoint. All access via Frappe or Cube."
  • "Cube SQL API — internal network only, or VPN for desktop Excel ODBC users."

But docker-compose.yml publishes ClickHouse ports 8123/9000/15432 to the host, .env.example ships weak default credentials, and profiles.yml uses secure: false.

Impact

The documented security model and the default deployment disagree. This is a classic "trusted the doc, got breached" gap.

Suggested fix

Either:

  • Harden the deployment to match the doc (bind to 127.0.0.1, proxy-only access, TLS), or
  • Update the doc to state plainly that the default compose is a local-dev profile and list the exact steps required for a network-isolated production deployment.

Also add a short section covering Airbyte connector security (credential storage, OAuth app registration), which the doc currently omits.

Related

Tickets: #34

Discussion

  • Anonymous

    Anonymous - 2026-06-13

    Originally posted by: pyy3

    Fixed in [#34] (merged to main).

     

    Related

    Tickets: #34

  • Anonymous

    Anonymous - 2026-06-13

    Ticket changed by: pyy3

    • status: open --> closed
     

Log in to post a comment.