Security posture
OpenDome handles tenant data, policy enforcement and access control. This page summarizes the security properties you can rely on — and verify — as a self-hoster.
Supply chain: signed, digest-pinned images
Section titled “Supply chain: signed, digest-pinned images”Released container images are published by immutable digest
(repo@sha256:…) to registry.gitlab.com/opendome.eu/platform/<cell> and
signed keyless with the GitLab CI OIDC identity (Fulcio certificate,
recorded in the public Rekor transparency log). The release pipeline writes the
tag and digest into every chart’s values, so checking out a release tag
means deploying exactly the scanned, signed artifacts.
Verify before deploying:
IMAGE=registry.gitlab.com/opendome.eu/platform/tenant-semantic-apiDIGEST=$(git show <tag>:charts/tenant-semantic-api/values.yaml | yq '.image.digest')
cosign verify "${IMAGE}@${DIGEST}" \ --certificate-oidc-issuer "https://gitlab.com" \ --certificate-identity-regexp "^https://gitlab.com/opendome.eu/platform//.gitlab-ci.yml@refs/(heads/main|tags/.*)$"Repeat per cell image (same pattern per chart values file). The full procedure is the repository’s publication runbook.
CI gates on every release
Section titled “CI gates on every release”- Trivy scan — no unresolved HIGH/CRITICAL findings (each accepted finding requires a written justification), blocking.
- SBOM — a software bill of materials is produced per image.
- OSS boundary gates —
scripts/oss-gate.shand the static gates assert the standalone invariant (the cell works with no control plane) and that no internal references leak into the public tree. - Version pinning — no
:latestanywhere; an image-pull gate confirms every default chart image is pinned and pulls anonymously.
Fail-closed enforcement, on by default
Section titled “Fail-closed enforcement, on by default”- The policy enforcement point is enabled by default and fails closed: a
governed query with no PDP snapshot is denied (
503 E2001), not served. - Identity comes only from a verified
Authorization: BearerActorToken — no trusted headers, no header-trust switch,alg=nonerejected, invalid token → hard401 E3001(see Authentication). - Retrieval and content previews are deny-by-default: a subject with no roles gets zero passages; redaction happens server-side in the cell.
- The cross-modal join key gate, the R3 firewall and the redaction-version isolation are structural, not configuration — see Access & capabilities.
The core of this enforcement model is backed by a machine-checked proof: the OSL research paper proves provenance preservation and denied-content non-interference for the compiled policy over an abstract model of the query plans, mechanized in Lean 4 — together with an explicit list of what is not proved. See Formal guarantees.
Network posture
Section titled “Network posture”The cell namespace ships a deny-all NetworkPolicy. The only holes are the
explicit allowlists you configure: the Kubernetes API egress CNPG needs, the
connectorRunnerEgress CIDRs for your sources, and the external
embedder endpoint. Trino, Lance and dbt expose no
public endpoint — the OSL engine is the only consumption surface.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Do not open a public issue. Report privately, per
SECURITY.md:
- GitLab confidential issue (preferred) — tick “This issue is confidential” when opening it.
- Email —
security@opendome.eu.
Expect acknowledgement within 3 business days and an initial severity assessment within 10. Security fixes land on the latest CalVer release line — there are no backports, so track the most recent release (see Releases & versioning).