Update Security docs (#2368)

* Rewrite security page intro to be feature-forward

Replaces the generic opening paragraph with one that names each security
feature (API key auth, read-only keys, JWT RBAC, network binding, TLS,
audit logging) and links directly to their sections, so scanning readers
see the full capability surface before hitting the warning block.

Also updates the checklist items to surface read-only keys and JWT RBAC
as explicit options under Authentication.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Add Security FAQ section to Qdrant Fundamentals

Adds three new Q&A entries covering default security posture, read-only
API keys, and JWT collection-scoped access control — the exact questions
users ask in Discord. Also adds Security to the page nav table and fixes
the heading depth on the collection-per-user entry (## → ###).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Add Security section to production checklist

Inserts a new section 2 covering the five key security steps — API key
auth, read-only keys, JWT access control, TLS, and network binding —
with direct links to the Security page. Renumbers existing sections
2–4 to 3–5. Closes the gap where a user following the checklist
step-by-step could go to production with an open, unauthenticated instance.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Link production checklist from both quickstart pages

Adds a production checklist callout to the "Next Steps" section of the
local quickstart and a bullet to the "What's Next?" section of the cloud
quickstart, so users completing either tutorial have a clear path to
production readiness.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Make code snippets testable

* Lead Security page by listing all the features; Rename API keys->Admin API keys, and 'Granular Access Control with JWT' section into 'Granular Access API Keys'

* Update links

* Update meta description

* Fix C# snippet

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Abdon Pijpelink
2026-05-27 15:56:52 +02:00
committed by GitHub
co-authored by Claude Sonnet 4.6
parent e64179bce0
commit 72ea635755
42 changed files with 396 additions and 218 deletions
+2 -2
View File
@@ -5611,7 +5611,7 @@ spec:
```
If you set the `jwt_rbac` flag, you will also be able to create granular [JWT tokens for role based access control](https://qdrant.tech/documentation/guides/security/#granular-access-control-with-jwt).
If you set the `jwt_rbac` flag, you will also be able to create granular [JWT tokens for role based access control](https://qdrant.tech/documentation/guides/security/#granular-access-api-keys).
### [Anchor](https://qdrant.tech/documentation/private-cloud/qdrant-cluster-management/\#configuring-tls-for-database-access) Configuring TLS for Database Access
@@ -47846,7 +47846,7 @@ export QDRANT__SERVICE__READ_ONLY_API_KEY=your_secret_read_only_api_key_here
Both API keys can be used simultaneously.
### [Anchor](https://qdrant.tech/documentation/guides/security/\#granular-access-control-with-jwt) Granular access control with JWT
### [Anchor](https://qdrant.tech/documentation/guides/security/\#granular-access-api-keys) Granular access control with JWT
_Available as of v1.9.0_