Clone
2
Security
Patrick Gniza edited this page 2026-08-17 10:48:39 +02:00

Deutsch | English

Security

Repository Security

The repository must not contain proprietary Romexis application binaries.

Installer packages are downloaded during payload builds from official URLs.


Secrets

Sensitive values should come from:

.env
Drone secrets
Docker Compose environment
external secret stores

Important values:

MSSQL_SA_PASSWORD
ROMEXIS_DB_PASSWORD
FIREBIRD_PASSWORD
MIGRATION_API_TOKEN
SFTP passwords
Registry credentials

Migration Service Security

Migration jobs create temporary SFTP credentials.

Rules:

  • credentials should be unique per job
  • credentials should be removed after completion
  • cancelled jobs should remove credentials
  • completed jobs should not recreate SFTP users on startup
  • failed jobs should not recreate SFTP users unless explicitly reactivated

Network Exposure

Expose only required ports.

Typical ports:

Romexis RMI ports
MSSQL 1433, if external access is required
Firebird 3050, if external access is required
Migration Web UI 8080
Migration SFTP 2222

For production, place services behind appropriate firewall rules.


File Permissions

Persistent directories must be writable by the relevant container users.

Special care is required for:

/var/opt/mssql
/firebird/data
/data/romexis_images
/data/romexis_ergodata
/data/romexis_cache

Production Notes

Before production use:

  • change all default passwords
  • restrict exposed ports
  • use HTTPS/reverse proxy for the migration Web UI
  • use strong API tokens
  • remove test migration jobs
  • verify backup/restore procedures