Skip to content
Ricklayer
RUEN
← Home

Servers and security

A product only starts at release

It has to stay alive, fast and closed. That part is entirely ours: from firewall rules to the sandbox of every service.

0

product services running as root

1.3

systemd-analyze score, out of 10

12

threat classes for every module

1

command to deploy with rollback

Services

Never root
A separate user per service: the site, the demo parser, licensing, the game server.
systemd sandbox
NoNewPrivileges, ProtectSystem=strict, private /tmp, empty capability set, syscall filter, writes only to allowed directories.
Loopback ports
Apps and databases listen on 127.0.0.1 only, nginx or Caddy face the outside.

Network and access

Firewall
ufw deny by default, fail2ban, key-only SSH.
Internals closed
RCON and databases are never exposed, staging sits behind basic auth.
Tunnels
LLM providers block Russia: requests go through a SOCKS tunnel to a node abroad with strict host key checking.

Application

Admin sign-in
Gate, password and 2FA on HMAC-signed host-only cookies. Five wrong codes burn the attempt, per-account limits.
Headers
CSP without unsafe-inline, HSTS, no framing, source maps disabled.
Audit
Admin actions are logged, anomalies are sent to Telegram as alerts.

Data and deploys

Encryption
Personal fields stored as AES-256-GCM, game account credentials wiped when an order closes.
Backups
Nightly, copies off the server, verified by restoring into an empty database.
Deploys
DB snapshot, migrations, build, release switch, health check and automatic rollback within a minute.

Incidents and findings

Incident 01 · open

The client chose the request host

nginx did not overwrite X-Forwarded-Host and the app read the host from it. A storefront request with a forged header got the admin sign-in form.

Incident 02 · open

Password reset bypassed 2FA

The emailed link gave an admin a session without the gate or second factor. Access to the admin mailbox bypassed both layers.

Incident 03 · open

Production disk at 93%

Monitoring showed 8 GB free out of 116. The tournament server was recording a demo around the clock.

Incident 04 · open

The demo parser took the site down

Parsing large demos ate memory, and the OOM killer took neighbouring processes along with the site.