Production checklist
Do these steps before your installation goes live. Each step links to the page with the details. The checklist contains only the steps that you must do. It does not contain the security controls that CIVITAS/CORE turns on by default. The steps under "Operator responsibilities" are the operator requirements of BSI TR-03187 level 1.
Cluster
- The cluster has enough nodes and resources for high availability → Cluster Requirements
- Linkerd and Kyverno are installed → Optional Cluster Components
- The CNI plugin enforces NetworkPolicies → Network Policies
- The ingress controller is meshed → Service Mesh Authorization
Configuration
-
profileisproduction→ Global settings -
clusterIssuernames an issuer of a trusted CA → Global settings - The
keycloak-smtpSecret has valid SMTP credentials → Installation - Your
deployment/directory is in a private git repository → Create the deployment directory - You did not weaken the security defaults → Already Implemented
- You decided which possible extensions you need → Possible Extensions
Operator responsibilities (TR-03187)
- All admins use MFA → Admin MFA
- Admins access the cluster and the nodes only with keys or certificates → Infrastructure Access
- The nodes run only the services that they need → Cluster Nodes
- The ingress sets HSTS and allows only your own origins → HSTS and CORS
- Volumes, etcd and backups are encrypted at rest → Encryption at Rest
- Access to managed services uses no static credentials → Managed Services
- Your VPN, if you use one, is configured securely → VPN
- Logs are stored centrally, protected, and have a retention period → Log Storage
Operation
- Backups are scheduled → Backup & Restore
- You tested a restore → Restore Procedures
- Metrics, logs and alerts are set up → Monitoring & Logging
- You know how to update → Updating
- You patch known vulnerabilities in a defined time → Vulnerability Management
- You test updates on a staging environment first → Test Environment