Security¶
How sslsync protects your secrets and servers.
- Secrets only in
.env: git-ignored, refused unlesschmod 600. The sudo password goes over stdin (sudo -S) and never appears in a process list. The private key is never logged or printed. - Host keys are always verified. A changed key is a hard stop.
_INSECURE_HOST_KEYexists for lab machines only. - Uploads go to a
umask 077temp dir that is removed afterwards, and are verified by sha256. - Key permissions are never left loose. New key files are created
0600. An existing key that other users can read is tightened during deploy (checkreports it first), and the old mode is restored on rollback. Kubernetes staging copies are always0600. Set_<TARGET>_KEY_MODE=0640when a service group must read the key. - Least change: identical files are not touched, and services whose files did not change are not reloaded.
certs/,logs/,reports/are git-ignored. Keep the CA account password and.pfxfiles in a password manager, not in this folder.- Prefer SSH keys (
_SSH_KEY) over passwords where the server allows it.
Found a problem? Report it privately: see the security policy.
What is never stored or sent anywhere¶
- Passwords are read from
.env, held in memory, and sent only to the server they belong to (SSH, thensudo -Son stdin). - The private key goes only to the servers that list it, over SSH, into a
umask 077temp directory. - sslsync makes no network connections other than to your servers. There is no telemetry and no update check.
The repository itself¶
.gitignoreexcludes.env,certs/,logs/andreports/..dockerignorekeeps them out of images.- CI fails if a
.pem,.key,.crt,.pfxor.envfile is committed, and scans every commit with gitleaks. - Releases are signed (cosign) and carry build provenance, so you can verify a binary came from this repository's workflow. See Releases & CI/CD.
Known advisories¶
GO-2026-5932 is reported by scanners against golang.org/x/crypto, because its openpgp package is unmaintained and has no fix. sslsync does not import the openpgp package, so it is not affected. It is listed in osv-scanner.toml with that reason.
govulncheck runs in CI on every pull request and fails on any reachable vulnerability.