We share responsibility for the security of your project: we secure the platform, check images and volumes, and strictly isolate projects from one another. You keep the software in your containers up to date and protect access.
Image scanning
We check every version of an image for known vulnerabilities before it is started for the first time (Creating a container). On a container’s page, the Security Check card displays the findings by severity: critical, high, medium and low. We check newer versions automatically. If there is a checked version with fewer findings, the card recommends it - use Prepare update to select it in the settings, then save. The Security tab summarises the results of all containers in your project (Security tab).
Nightly scan of the volumes
Every night, we scan the files in your volumes with the ClamAV virus scanner and with patterns for typical malicious code, such as hidden PHP backdoors. If the scan detects anything, you will receive an email, and a security warning will appear in the customer area - in the dashboard and in the project overview. Your project will continue to run as normal.
A warning may indicate an attack, but it could also be a false alarm. Proceed as follows:
- Check the files found - open the volume in the file browser (Storage and file browser). Remove any unknown files from there.
- Restore a state from before the incident - you can find snapshots and backups in the Backup & Snapshot tab.
- Update software, change passwords - update applications, themes and plugins, and change all passwords, including those stored in your secrets.
Our team also looks into the finding and get in touch if they have any questions.
Quarantine
In the event of a confirmed incident, such as an attack originating from your project, our team may place the project in quarantine. In this case:
- The project is disconnected from the network: your containers have no external connection, and web addresses and custom ports are disabled.
- Your containers will continue to run. Files, logs, snapshots and backups will remain available to you so that you can clean up.
- The notification in the project will state the date and reason.
Clean up the project - for example, using a snapshot taken before the incident - update your software and change all your passwords. Then contact Support so that we can lift the quarantine.
Recommendations for a secure project
- Use checked versions and switch to recommended versions with fewer findings.
- Mark passwords and keys as secret (environment variables and secrets).
- Operate databases on an internal network without internet access (networks and firewall).
- Protect administration interfaces with an IP allowlist or a password (Making a container reachable on the web).
- Enable automatic snapshots and book backups.