Skip to content

docs: add SECURITY.md and ignore credential file patterns - #22

Merged
saqibmanan merged 2 commits into
mainfrom
docs-public-release-hygiene
Sep 8, 2026
Merged

saqibmanan merged 2 commits into
mainfrom
docs-public-release-hygiene

Conversation

@saqibmanan

Copy link
Copy Markdown
Contributor

Preparing this repository to be made public.

Audit result first

check_public_ready.sh reports 0 fails. The detail, because "0 fails" alone is not evidence:

Check Result
Tracked forbidden files none
.env / .pem / .key ever committed none, in 634 commits
EC2 IP in history 0 commits
Private key blocks in history 0 commits
Passwords in history only ${KEYCLOAK_PASSWORD} — a variable reference
trufflehog verified secrets none

gitleaks reports 4 findings; all four are false positives — the same reCAPTCHA site key in Storybook fixtures. Site keys are public by design (they ship in the HTML of any page using reCAPTCHA), and this one comes from the upstream Keycloakify starter template, dated 2024-06-05.

Secrets were correctly kept in the host's .env and in GitHub environment secrets throughout.

SECURITY.md

Matters more than usual here: this theme renders the login, registration and account pages that every CivicDataLab product authenticates through. A finder needs a private route to report, rather than opening a public issue on an auth surface.

Points at GitHub private advisories first, info@civicdatalab.in as fallback, sets scope, and routes Keycloak/Keycloakify findings upstream where they actually get fixed.

.gitignore

Preventative, not corrective — nothing has leaked. These patterns are what keeps that true once the repo is public and mistakes become permanent and world-readable.

Adds .env and variants, *.pem, *.key, *.p12, keystores, id_rsa/id_ed25519, plus the Python tooling patterns the audit flagged. .env.example is explicitly re-included so the documented template still ships.

Verified no currently tracked file matches the new patterns, so nothing silently drops out of the index.

After going public

Rulesets, branch protection, required reviewers and wait timers all become available — currently every one returns 403 on the free plan for a private repo. That is the protection worth adding for a production auth deploy.

Preparing this repository to be made public.

SECURITY.md matters more than usual here: this theme renders the login,
registration and account pages that every CivicDataLab product
authenticates through, so a finder needs a private route to report
rather than opening a public issue on an auth surface. Points at GitHub
private advisories first and info@civicdatalab.in as a fallback, sets
scope, and routes Keycloak and Keycloakify findings upstream where they
belong.

The .gitignore additions are preventative rather than corrective.
Nothing sensitive has ever been committed - 634 commits were scanned
before this change and found no .env, no key material and no
credentials, only variable references such as ${KEYCLOAK_PASSWORD} - and
these patterns are what keeps that true once the repository is public
and mistakes become permanent.

.env.example is explicitly re-included so the documented template still
ships.

Verified no currently tracked file matches the new patterns, so nothing
silently drops out of the index.
The README was still the unmodified Keycloakify starter template. It
described a generic starter's release workflow and said nothing about
what this repository actually is, where it deploys, or that a bad merge
signs every CivicDataLab user out of every product.

Leads with four badges so the repository home shows deploy and CI state
at a glance - the quality gate is visible rather than something you have
to open the Actions tab to learn. The Actions badges render once the
repository is public; they 404 while it is private, which is expected.

Documents what the starter README could not:

- auth.civicdatalab.in is production, and which products depend on it
- merging to main deploys; pushing to dev does not
- the deploy path, including the health gate and automatic rollback
- that the rollback is NOT a complete safety net, because a Keycloak
  major upgrade migrates the schema one-way and the older image cannot
  start against it - hence the pg_dump before every deploy
- why the post-deploy tests live in CivicDataSpace-test: the theme ships
  independently of the applications, so a theme change can break sign-in
  while every product's own pipeline stays green
- which jar to use and why copying both breaks theme selection
- the identifiers that still say "staging" and must not be renamed, with
  the consequence of each

Keeps the genuinely useful starter content - local setup, Maven
requirement, account and email theme initialisation - and drops the
starter's release instructions, which do not apply here.
@saqibmanan
saqibmanan merged commit 4e8f4dc into main Sep 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant