Administration
Security
Harden hosts, cookies, headers, encrypted data and high-risk modules.
Security
Open Site Administration > Security. Configure trusted-host enforcement only after entering every required hostname/IP. Choose the frame-ancestor policy and optional sources, enable HSTS only after HTTPS works, and set the RDP token lifetime between 5 and 60 minutes.
The current-request checks help verify allowed host, inbound DNS, outbound public IP, framing, HSTS and effective client/proxy state. Some tests use external DNS or public-IP services and can fail because of network policy.
Kaya hashes passwords with Argon2, encrypts stored operational secrets, applies Strict SameSite session cookies, validates CSRF on browser mutations and writes audit records. It is still the operator's responsibility to use HTTPS, protect bind mounts and backups, patch images, limit Admin roles and segment management traffic.
Current limitations include in-memory rate limits, coarse route-level RBAC, no general malware scanner and background tasks within the web process.
