Your Caddy Admin API Is a Deployment Interface - Treat It Like Root
The admin endpoint can replace active configuration, so broad exposure changes the security boundary of the edge.
The admin endpoint can replace active configuration, so broad exposure changes the security boundary of the edge.
Convenient arbitrary shell access would collapse the separation between reviewed operations and unrestricted host control.
A probe that follows a redirect can report success for the wrong endpoint and hide an authentication or routing failure.
Sharing SIP credentials across devices makes revocation, auditing and fleet diagnosis ambiguous.
Keeping host execution outside the portal containers limits what a web compromise can directly control.
How I separate east-west service communication from user-facing exposure.
Repeated sudo failures may be operator error, expired credentials or suspicious privilege-escalation attempts, and they often happen outside application logs.
A device should decide whether firmware is authorized, not merely whether the download completed successfully.
Reading outputs from another Terraform state is convenient, but consumers generally need access to the full underlying state snapshot. That couples security and deployment boundaries.
How to think about credentials when application manifests are intentionally stored in Git.
A few failed SSH logins are normal on an administered server, while a rapid burst can indicate brute-force activity or a broken automation credential.
My first memorable ACL mistake was technically correct: it blocked exactly what I told it to block, including the management traffic I still needed.
Moving alert delivery to authenticated self-hosted ntfy introduced a publisher token that the alert-sink needs at runtime.
If a token only needs to be checked, retaining the plaintext creates unnecessary breach impact.
Identity headers are safe only when clients cannot inject equivalent values around the auth boundary.
Security logs contain useful source addresses, but promoting every IP to a Prometheus or Loki index label would create unbounded cardinality on an Internet-facing service.
Moving from local console access to SSH keys changed the lab from a collection of machines into something I could actually operate and troubleshoot remotely.
Control-plane actions are easier to trust when later updates cannot silently replace the original event record.
WebAuthn can prove possession of a scoped private key. The product still has to reason about synced credentials, discoverable accounts, conditional UI, recovery, re-registration, and what the browser chooses to show.
Long-lived trusted-browser sessions change the authentication risk model and should be chosen deliberately.
Once the tailnet becomes a real operational network, who can reach which host and service should not live only in memory.
A firmware artifact can be newer and still be unsafe for the target partition table, bootloader or hardware revision.
Product restraint changes threat modeling as much as it changes UX.
A successful secret request is operationally normal and still important enough to leave durable evidence.