mirror of
https://github.com/qdrant/landing_page.git
synced 2026-09-28 23:48:31 +02:00
Merge pull request #814 from qdrant/fix/mac/more-secure-deployment-advice
Add container hardening advice
This commit is contained in:
@@ -43,13 +43,17 @@ All Qdrant instances in a cluster must be able to:
|
||||
- Communicate with each other over these ports
|
||||
- Allow incoming connections to ports `6333` and `6334` from clients that use Qdrant.
|
||||
|
||||
### Security
|
||||
|
||||
The default configuration of Qdrant might not be secure enough for every situation. Please see [our security documentation](/documentation/guides/security/) for more information.
|
||||
|
||||
## Installation options
|
||||
|
||||
Qdrant can be installed in different ways depending on your needs:
|
||||
|
||||
For production, you can use our Qdrant Cloud to run Qdrant either fully managed in our infrastructure or with Hybrid SaaS in yours.
|
||||
For production, you can use our Qdrant Cloud to run Qdrant either fully managed in our infrastructure or with Hybrid SaaS in yours.
|
||||
|
||||
For testing or development setups, you can run the Qdrant container or as a binary executable.
|
||||
For testing or development setups, you can run the Qdrant container or as a binary executable.
|
||||
|
||||
If you want to run Qdrant in your own infrastructure, without any cloud connection, we recommend to install Qdrant in a Kubernetes cluster with our Helm chart, or to use our Qdrant Enterprise Operator
|
||||
|
||||
@@ -59,7 +63,7 @@ For production, we recommend that you configure Qdrant in the cloud, with Kubern
|
||||
|
||||
### Qdrant Cloud
|
||||
|
||||
You can set up production with the [Qdrant Cloud](https://qdrant.to/cloud), which provides fully managed Qdrant databases.
|
||||
You can set up production with the [Qdrant Cloud](https://qdrant.to/cloud), which provides fully managed Qdrant databases.
|
||||
It provides horizontal and vertical scaling, one click installation and upgrades, monitoring, logging, as well as backup and disaster recovery. For more information, see the [Qdrant Cloud documentation](/documentation/cloud/).
|
||||
|
||||
### Kubernetes
|
||||
@@ -81,7 +85,7 @@ We provide a Qdrant Enterprise Operator for Kubernetes installations. For more i
|
||||
|
||||
Usually, we recommend to run Qdrant in Kubernetes, or use the Qdrant Cloud for production setups. This makes setting up highly available and scalable Qdrant clusters with backups and disaster recovery a lot easier.
|
||||
|
||||
However, you can also use Docker and Docker Compose to run Qdrant in production, by following the setup instructions in the [Docker](#docker) and [Docker Compose](#docker-compose) Development sections.
|
||||
However, you can also use Docker and Docker Compose to run Qdrant in production, by following the setup instructions in the [Docker](#docker) and [Docker Compose](#docker-compose) Development sections.
|
||||
In addition, you have to make sure:
|
||||
|
||||
* To use a performant [persistent storage](#storage) for your data
|
||||
@@ -170,7 +174,7 @@ services:
|
||||
configs:
|
||||
qdrant_config:
|
||||
content: |
|
||||
log_level: INFO
|
||||
log_level: INFO
|
||||
```
|
||||
|
||||
<aside role="status">Proving the inline <code>content</code> in the <a href="https://docs.docker.com/compose/compose-file/08-configs/">configs top-level element</a> requires <a href="https://docs.docker.com/compose/release-notes/#2231">Docker Compose v2.23.1</a> or above. This functionality is supported starting <a href="https://docs.docker.com/engine/release-notes/25.0/#2500">Docker Engine v25.0.0</a> and <a href="https://docs.docker.com/desktop/release-notes/#4260">Docker Desktop v4.26.0</a> onwards.</aside>
|
||||
|
||||
@@ -9,7 +9,7 @@ aliases:
|
||||
|
||||
|
||||
|
||||
Please read this page carefully. Although there are various ways to secure your Qdrant instances, **they are unsecured by default**.
|
||||
Please read this page carefully. Although there are various ways to secure your Qdrant instances, **they are unsecured by default**.
|
||||
You need to enable security measures before production use. Otherwise, they are completely open to anyone
|
||||
|
||||
## Authentication
|
||||
@@ -229,3 +229,20 @@ tls:
|
||||
# Required if cluster.p2p.enable_tls is true.
|
||||
ca_cert: ./tls/cacert.pem
|
||||
```
|
||||
|
||||
## Hardening
|
||||
|
||||
We recommend reducing the amount of permissions granted to Qdrant containers so that you can reduce the risk of exploitation. Here are some ways to reduce the permissions of a Qdrant container:
|
||||
|
||||
* Run Qdrant as a non-root user. This can help mitigate the risk of future container breakout vulnerabilities. Qdrant does not need the privileges of the root user for any purpose.
|
||||
- You can use the image `qdrant/qdrant:<version>-unprivileged` instead of the default Qdrant image.
|
||||
- You can use the flag `--user=1000:2000` when running [`docker run`](https://docs.docker.com/reference/cli/docker/container/run/).
|
||||
- You can set [`user: 1000`](https://docs.docker.com/compose/compose-file/05-services/#user) when using Docker Compose.
|
||||
- You can set [`runAsUser: 1000`](https://kubernetes.io/docs/tasks/configure-pod-container/security-context) when running in Kubernetes (our [Helm chart](https://github.com/qdrant/qdrant-helm) does this by default).
|
||||
|
||||
* Run Qdrant with a read-only root filesystem. This can help mitigate vulnerabilities that require the ability to modify system files, which is a permission Qdrant does not need. As long as the container uses mounted volumes for storage (`/qdrant/storage` and `/qdrant/snapshots` by default), Qdrant can continue to operate while being prevented from writing data outside of those volumes.
|
||||
- You can use the flag `--read-only` when running [`docker run`](https://docs.docker.com/reference/cli/docker/container/run/).
|
||||
- You can set [`read_only: true`](https://docs.docker.com/compose/compose-file/05-services/#read_only) when using Docker Compose.
|
||||
- You can set [`readOnlyRootFilesystem: true`](https://kubernetes.io/docs/tasks/configure-pod-container/security-context) when running in Kubernetes (our [Helm chart](https://github.com/qdrant/qdrant-helm) does this by default).
|
||||
|
||||
There are other techniques for reducing the permissions such as dropping [Linux capabilities](https://www.man7.org/linux/man-pages/man7/capabilities.7.html) depending on your deployment method, but running as a non-root user with a read-only root file system are the two most important.
|
||||
|
||||
Reference in New Issue
Block a user