Operations
Security
AstroGuide's actual scope, HTTP headers and safe exposure practices.
AstroGuide is a static application without a backend, user accounts or API keys. The relevant attack surface is the dependency chain, Docker image, GitHub Actions workflows, HTTP headers and browser.
Container headers
nginx.conf sends, among others:
X-Content-Type-Options: nosniffReferrer-Policy: no-referrerPermissions-Policy: camera=(), geolocation=(), microphone=()- a CSP restricted to
'self', withimg-srcallowingdata:andblob:, andstyle-srcallowing'unsafe-inline'
server_tokens is disabled and the Nginx process does not run as root.
Vercel demo headers
The product's vercel.json applies an equivalent CSP, plus X-Robots-Tag: noindex, nofollow, noarchive and frame-ancestors 'none'.
Recommendations
- prefer an HTTPS reverse proxy when publishing outside your LAN;
- do not present a private instance as the official demo: use demo.astroguide.lucas-homelab.fr;
- report vulnerabilities through the Security policy, not a public issue.
AstroGuide has no JWT, session cookie or secret environment variable to rotate.