If you discover a security vulnerability in this project, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, email: security@estabilis.io
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 48 hours and provide a timeline for the fix.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Previous minor | Best effort |
| Older | No |
When deploying this module in production:
- Disable local accounts: Set
local_account_disabled = truewith Azure AD group IDs - Restrict API server access: Set
authorized_ip_rangesto platform NAT gateway IP only - Enable resource locks: Set
storage_protect_critical = trueon critical storage - Use Private Endpoints: Where available (ACR Premium)
- Rotate credentials: Regularly rotate Docker Hub tokens and hub registrar tokens
- Monitor audit logs: Enable
diagnostics_enabled = truewith Log Analytics