GuidesDeploy MDK

Harden your deployment

Production security hardening.

Status: Gap

The v0.4 docs expose no adequate canonical source; this is largely net-new content.

This is a v0.5 information-architecture stub. It marks where this topic belongs in the proposed Diátaxis structure and tracks what already exists versus what still needs to be written. The complete current docs remain in the frozen v0.4 archive.

The current material is fragments (auth/RBAC claims, OAuth in a tutorial, noAuth warnings), not a hardening guide.

What exists today

Related v0.4 pages (archived, frozen):

What's needed for 0.5

  • Trust boundaries; TLS and network exposure.
  • Secrets and credential handling.
  • Authentication and RBAC setup; allowlisting.
  • Least privilege; service identity; audit logging.
  • Secure defaults and validation/checklist evidence.

On this page