Skip to content

Commit 46fb69d

Browse files
authored
Merge pull request #12006 from tsuretettee/develop
Add security warning to production container guide
2 parents c26812e + c6c0a97 commit 46fb69d

File tree

1 file changed

+10
-2
lines changed

1 file changed

+10
-2
lines changed

doc/sphinx-guides/source/container/running/production.rst

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,14 @@
11
Production
22
==========
33

4+
.. _production-security-warning:
5+
6+
.. warning::
7+
8+
The :doc:`demo` tutorial is **NOT SECURE BY DEFAULT**. It uses public, hardcoded passwords and secrets for demonstration purposes only.
9+
10+
If you use the demo as a structural template, you MUST replace all default secrets before deploying your instance. Failure to do so will result in a vulnerable production environment.
11+
412
.. contents:: |toctitle|
513
:local:
614

@@ -11,7 +19,7 @@ As of Dataverse 6.8, when we introduced image tagging per version (see the :ref:
1119

1220
The images and the documentation is not perfect, of course.
1321

14-
For now, we recommend following the :doc:`demo` tutorial. It will help you learn how to configure and secure your installation. Not that instead of "latest" you might want to select a specific version. Again see :ref:`app-image-supported-tags`.
22+
For now, we recommend following the :doc:`demo` as a structural template. Note that instead of "latest" you might want to select a specific version. Again see :ref:`app-image-supported-tags`.
1523

1624
The Dataverse guides were originally written with a non-Docker installation in mind so we'd like rewrite them with both Docker and non-Docker in mind. This is a big job, obviously. 😅 We know we'd like to write more about ports. We'd like to explain `how to set up Rserve <https://github.com/IQSS/dataverse/issues/11731>`_. Etc., etc.
1725

@@ -30,4 +38,4 @@ Please try the images (see :doc:`demo`) and give feedback (see :ref:`helping-con
3038
Alternatives
3139
------------
3240

33-
The traditional (non-Docker) installation method is described in the :doc:`/installation/index`.
41+
The traditional (non-Docker) installation method is described in the :doc:`/installation/index`.

0 commit comments

Comments
 (0)