Security

Best practices

  • Run InfraPilot behind a reverse proxy with HTTPS, never expose port 3000 directly
  • Use a strong, unique NEXTAUTH_SECRET (32+ random characters)
  • Enable two-factor authentication (Settings → Security → 2FA)
  • Restrict dashboard access via your firewall to trusted IP ranges when possible
  • Rotate agent tokens periodically and immediately if a server is decommissioned
  • Keep InfraPilot updated, run `docker compose pull && docker compose up -d` regularly

Reporting vulnerabilities

Found a security issue? Please disclose responsibly by emailing security@infrapilot.org. We aim to acknowledge reports within 24 hours and resolve critical issues within 72 hours.

Still need help?

Open an issue on GitHub or reach out to our support team.