Security Best Practices
This document defines the baseline security expectations for SkyCloud-managed systems and operations.
Security Philosophy
Security should be operationally practical, consistently applied, and integrated into normal infrastructure management.
Core Security Standards
- All public services should use HTTPS
- Administrative access should remain restricted
- Strong passwords are mandatory
- Credentials should never be shared insecurely
- Unused services should not remain publicly exposed
Infrastructure Security Expectations
- Reverse proxy routing should remain controlled
- Production systems should avoid unnecessary exposure
- DNS and Cloudflare access should remain protected
- TLS certificates should be monitored routinely
- Security updates should be reviewed regularly
Operational Security Rules
- Do not perform risky changes without backups
- Do not leave temporary credentials active
- Do not expose internal dashboards publicly without protection
- Investigate unusual authentication activity promptly
Incident Expectations
Potential security incidents should be escalated immediately and documented carefully.