Skip to content

Security posture

OpenDome handles tenant data, policy enforcement and access control. This page summarizes the security properties you can rely on — and verify — as a self-hoster.

Supply chain: signed, digest-pinned images

Section titled “Supply chain: signed, digest-pinned images”

Released container images are published by immutable digest (repo@sha256:…) to registry.gitlab.com/opendome.eu/platform/<cell> and signed keyless with the GitLab CI OIDC identity (Fulcio certificate, recorded in the public Rekor transparency log). The release pipeline writes the tag and digest into every chart’s values, so checking out a release tag means deploying exactly the scanned, signed artifacts.

Verify before deploying:

Terminal window
IMAGE=registry.gitlab.com/opendome.eu/platform/tenant-semantic-api
DIGEST=$(git show <tag>:charts/tenant-semantic-api/values.yaml | yq '.image.digest')
cosign verify "${IMAGE}@${DIGEST}" \
--certificate-oidc-issuer "https://gitlab.com" \
--certificate-identity-regexp "^https://gitlab.com/opendome.eu/platform//.gitlab-ci.yml@refs/(heads/main|tags/.*)$"

Repeat per cell image (same pattern per chart values file). The full procedure is the repository’s publication runbook.

  • Trivy scan — no unresolved HIGH/CRITICAL findings (each accepted finding requires a written justification), blocking.
  • SBOM — a software bill of materials is produced per image.
  • OSS boundary gates — scripts/oss-gate.sh and the static gates assert the standalone invariant (the cell works with no control plane) and that no internal references leak into the public tree.
  • Version pinning — no :latest anywhere; an image-pull gate confirms every default chart image is pinned and pulls anonymously.
  • The policy enforcement point is enabled by default and fails closed: a governed query with no PDP snapshot is denied (503 E2001), not served.
  • Identity comes only from a verified Authorization: Bearer ActorToken — no trusted headers, no header-trust switch, alg=none rejected, invalid token → hard 401 E3001 (see Authentication).
  • Retrieval and content previews are deny-by-default: a subject with no roles gets zero passages; redaction happens server-side in the cell.
  • The cross-modal join key gate, the R3 firewall and the redaction-version isolation are structural, not configuration — see Access & capabilities.

The core of this enforcement model is backed by a machine-checked proof: the OSL research paper proves provenance preservation and denied-content non-interference for the compiled policy over an abstract model of the query plans, mechanized in Lean 4 — together with an explicit list of what is not proved. See Formal guarantees.

The cell namespace ships a deny-all NetworkPolicy. The only holes are the explicit allowlists you configure: the Kubernetes API egress CNPG needs, the connectorRunnerEgress CIDRs for your sources, and the external embedder endpoint. Trino, Lance and dbt expose no public endpoint — the OSL engine is the only consumption surface.

Do not open a public issue. Report privately, per SECURITY.md:

  • GitLab confidential issue (preferred) — tick “This issue is confidential” when opening it.
  • Email — security@opendome.eu.

Expect acknowledgement within 3 business days and an initial severity assessment within 10. Security fixes land on the latest CalVer release line — there are no backports, so track the most recent release (see Releases & versioning).