Trust

Security posture สำหรับ managed Linux monitoring

Nova ออกแบบรอบ tenant-scoped access, short-lived collector enrollment, feature controls ที่ชัดเจน และ Linux monitoring scope ที่แคบ หน้านี้อธิบาย posture ปัจจุบันในช่วง private beta และจุดที่ยังต้อง review ก่อนใช้งานจริง

Access model
Tenant roles map เข้า Grafana org access ผ่าน OIDC
Collector enrollment
One-time installer tokens ถูก revoke, expire และ mark used หลัง exchange
Sensitive paths
Block path ที่มักเป็น private key และ system credentials สำหรับ file log monitoring
Beta limit
ยังไม่ claim public SOC 2, ISO 27001 หรือ penetration-test report

Tenant isolation และ roles

NovaUI สร้าง tenant records, map แต่ละ tenant กับ Grafana organization และใช้ role claims สำหรับ tenant admin, editor และ viewer access หน้า UI ที่เป็น tenant-scoped จะ resolve tenant ก่อนแสดง collectors, team members, limits หรือ billing status

นี่เป็น isolation model ระดับ application และ Grafana organization หาก prospect ต้องการ separation ที่เข้มกว่านี้ ควรคุยเรื่อง private deployment, network isolation และ data residency ก่อน rollout

Collector enrollment และ credentials

Collectors enroll ด้วย one-time node tokens เมื่อต้องสร้าง token ใหม่ active token เดิมจะถูก revoke, token มี expiry และ installer exchange จะ mark token ที่ valid ว่า used

หลัง enrollment collectors authenticate ด้วย generated credentials สำหรับ configuration และ telemetry routing NovaUI ติดตาม collector status จาก check-ins, config polls และ Alloy versions ที่ report กลับมา

  • Installer tokens เป็น bearer secrets และควรถูกจัดการแบบ sensitive
  • Collector credentials ไม่ควรถูกแสดงใน browser หรือ logs
  • Suspended tenants ไม่สามารถสร้าง installer tokens ใหม่ได้

Telemetry และ sensitive data

Nova V1 โฟกัส Linux host metrics, systemd journal logs, selected file log paths และ optional Docker telemetry การ validate file monitor ปัจจุบัน block absolute paths ที่มักมี private credentials เช่น shadow files และ private-key locations

ลูกค้ายังเป็นผู้ควบคุมว่า application เขียนอะไรลง logs Nova ช่วยเรื่อง collection defaults ได้ แต่ทีมควรหลีกเลี่ยงการ log passwords, access tokens, payment data, personal data หรือ application secrets

ข้อจำกัดปัจจุบัน

Nova ยังอยู่ใน private beta หน้านี้ไม่ควรถูกอ่านเป็น compliance certificate, audit report หรือ security warranty

ก่อน production rollout ลูกค้าควรยืนยัน TLS/proxy configuration, secure cookie behavior, staff account controls, retention policy, incident contacts และ security requirements ตาม contract