Production hardening¶
A default installation is not a hardened installation. This checklist lists the controls an operator must apply, and the verification that shows each one is actually in effect.
Identity and access¶
- Set
SLIMSTREAM_OIDC_ISSUER,SLIMSTREAM_OIDC_CLIENT_IDandSLIMSTREAM_OIDC_REQUIRED=trueon the Manager, so that a missing identity configuration fails closed. Verify with an unauthenticated request, which must be rejected. - Map identity-provider groups to Viewer, Operator and Admin, and keep Admin membership minimal. Verify by attempting an Admin-only operation with an Operator token.
- Use
auth_mode: managed_identityorauth_mode: workload_identityfor Sentinel. Verify that noclient_secretappears in any configuration version. - Scope Monitoring Metrics Publisher to the specific Data Collection Rule, not the subscription or resource group. Verify with a role-assignment listing at that scope.
- Issue a distinct Data Plane reload token per node and record its rotation owner.
Network exposure¶
- Terminate TLS at an ingress or reverse proxy for the Manager UI/API and the HTTP listener; Logstrm does not terminate TLS in-process. Verify the published endpoint negotiates TLS and rejects plaintext.
- Keep the Manager off the public internet. Expose it through a private endpoint, VPN or identity-aware proxy.
- Keep the Data Plane Service internal (
ClusterIP, the Helm chart default). If external ingestion needs a direct LoadBalancer, opt in explicitly and restrict it to trusted source networks; do not expose the Manager API or reload endpoint publicly. - Configure a hot-reload token from a Kubernetes Secret. The Helm chart now rejects missing or conflicting token configuration, and Secret references are required by both workloads; never rely on an unauthenticated reload endpoint.
- Keep the Syslog listener on a trusted segment; it supports TCP and UDP only and offers no TLS.
- Enable the chart's NetworkPolicy (
networkPolicy.enabled=true), which is disabled by default, and restrict ingress to the Manager and egress to the required destinations. Verify that a denied path actually fails. - Reject
insecure_skip_verifyand plainhttp://endpoints for the Elasticsearch emitter in configuration review.
Private connectivity to Azure Monitor¶
Private connectivity is a property of the deployment, not a Logstrm feature. Logstrm sends HTTPS to whatever Data Collection Endpoint it is given, so it inherits whatever path the network provides.
- Place the Data Plane in the customer VNet or an AKS cluster with controlled egress.
- Configure an Azure Monitor Private Link Scope with the Data Collection Endpoint and the workspace, and validate that private DNS resolves the ingestion hostname to the private endpoint address from inside the workload.
- Confirm ingestion still succeeds with public network access disabled on the relevant resources, and record that test as the evidence.
- Inventory the dependencies that remain outside the private path, such as Entra token endpoints, the container registry and the customer's identity provider, and permit them explicitly in egress rules.
Do not state "Private Link supported" without the resolution and ingestion evidence above; the distinction between private data-plane traffic and authentication egress is the one assessors check.
Data at rest¶
- Place the DLQ directory, any JSONL archive and the Manager database on encrypted volumes, with customer-managed keys where policy requires them.
- Apply the same encryption and access control to volume backups and snapshots.
- Configure masking or field removal in the pipeline so that buffered payloads contain no unnecessary sensitive data.
- Set DLQ retention and archive rotation to match the data-classification policy, and monitor DLQ growth.
See Data protection and encryption for what the product does and does not encrypt.
Workload and supply chain¶
- Keep the chart's container defaults: non-root user, read-only root filesystem, no privilege escalation, all capabilities dropped,
RuntimeDefaultseccomp,automountServiceAccountToken: falseand resource limits. Verify on the running pod specification rather than on values files alone. - Deploy images by digest, not by mutable tag.
- Verify the Cosign signature and SLSA provenance of every digest before promotion, as described in Image signatures and build provenance.
- Restrict registry pull credentials to the images required.
Operations¶
- Review configuration changes before rollout; treat configuration as production code and keep the previous version available for rollback.
- Ship Manager and Data Plane logs and metrics to monitoring, and alert on delivery failure, DLQ growth and authentication errors. See Observability.
- Test restoration of the Manager database and confirm which configuration state the restore produces.
- Define ownership for vulnerability remediation, image rebuilds and upgrade cadence.
- Record residual risks that this checklist cannot remove, such as the absence of application-level encryption and of in-process TLS, and obtain explicit acceptance for them.
Validation scope¶
Published Azure identity validations are controlled functional smoke tests: they demonstrate that an authentication mode successfully delivers a schema-matching event. They are not throughput, resilience, failover or production-readiness certifications, and they do not replace the customer's own acceptance testing in the target environment.