Security Settings

Besides Attack Mode, the Temps proxy applies three protections you configure: security headers on your apps' responses, an instance-wide IP access list, and vulnerability scans of deployed images. Security headers are off by default, the IP list blocks or allows addresses before a request reaches any app, and scans need Trivy on the Temps server. For the full security overview, see Security.


Security headers

Set security headers

  1. 1

    Choose a level: Global (Settings then Security then Security Headers) or Project (Project Settings then Security then Security Headers). The environment form also has a Security Headers switch, but the proxy ignores it in v0.1.0-beta.56.

  2. 2

    Turn on Enable Security Headers. In a project, pick a preset (Strict, Moderate, Permissive) or choose Custom to set Content-Security-Policy, X-Frame-Options, Strict-Transport-Security and Referrer-Policy yourself.

  3. 3

    Save the Security Headers configuration.

    Checkpoint: Run curl -sI against your app and confirm the response carries the four headers with the values listed for your preset below.

Security headers are configured exclusively via the dashboard or API -- there is no dedicated CLI command for this feature.

Temps can add four HTTP security headers to every response from your deployed applications: Content-Security-Policy, X-Frame-Options, Strict-Transport-Security and Referrer-Policy. They are off until you enable them, globally or for a project. A project that has its own security-headers setting uses it instead of the global one; the two are not merged.

What v0.1.0-beta.56 does not do, even though the dashboard shows the fields:

  • X-Content-Type-Options, X-XSS-Protection and Permissions-Policy can be edited in the global Custom form and are stored, but the proxy never sends them. Set those three in your app or framework.
  • The Security Headers switch and Header Preset in an environment's settings are saved but not read. Headers come from the project, or from the global setting when the project has none. Per-environment settings that do work are Attack Mode and the environment's Password Protection.
  • No preset generates CSP nonces. Every preset allows 'unsafe-inline' scripts; if you need a nonce-based policy, send the CSP from your app and leave Temps' header off.

Project presets

In Project Settings → Security → Security Headers, turn on Enable Security Headers and pick a preset. These are the exact values the proxy sends:

PresetContent-Security-PolicyX-Frame-OptionsStrict-Transport-SecurityReferrer-Policy
Strictdefault-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'DENYmax-age=31536000; includeSubDomains; preloadstrict-origin-when-cross-origin
Moderatedefault-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self' https:; frame-ancestors 'self'SAMEORIGINmax-age=31536000; includeSubDomainsno-referrer-when-downgrade
Permissivedefault-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors *ALLOW-FROM *max-age=31536000origin
CustomYour valueYour valueYour valueYour value
Disabled (API only)Not sentNot sentNot sentNot sent

Note that Strict is not stricter on scripts: it adds 'unsafe-eval', which Moderate does not allow. It is stricter on framing (DENY, frame-ancestors 'none'), connect-src, base-uri, form targets, referrers and HSTS preload. With Custom, only the headers you fill in are sent, and values you fill in under Custom keep being sent even if you switch back to a preset afterwards; clear them first. Turning the project's switch off, or setting the preset to disabled through the API (the dashboard has no Disabled option), sends no headers for that project and does not fall back to the global setting. The project's Enable Security Headers switch and its Rate Limiting switch save the same field, so they turn on and off together.

Global setting

Settings → Security → Security Headers applies to every project without its own security-headers setting. When you enable it, the proxy sends these stored values:

HeaderDefault value
Content-Security-Policydefault-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'self'
X-Frame-OptionsSAMEORIGIN
Strict-Transport-Securitymax-age=31536000; includeSubDomains
Referrer-Policystrict-origin-when-cross-origin

The global Security Preset selector (default Moderate) stores the preset name but does not change these values in v0.1.0-beta.56: picking Strict or Permissive there sends the same four values. To change what the global setting sends, choose Custom and edit the fields.

Configuring Headers

Dashboard vs API

1. Global:  Settings → Security → Security Headers
2. Project: Project Settings → Security → Security Headers

IP access control

Block an IP

  1. 1

    Go to Settings then Security then IP Access Control.

  2. 2

    Click Add Rule.

  3. 3

    Enter the IP address or CIDR range (for example 192.168.1.100 or 10.0.0.0/8).

  4. 4

    Select Block. (Allow rules are saved but not enforced in v0.1.0-beta.56.)

  5. 5

    Optionally add a reason for audit purposes.

  6. 6

    Save the rule.

    Checkpoint: Block rules take effect within about 30 seconds; confirm the new rule appears in the IP Access Control list.

Block clients by IP address or CIDR range at the proxy, before requests reach your applications. There is one list for the whole instance, so every block rule applies to every project.

Per-project and per-environment IP allow and deny lists are part of Temps Premium.

Block List

Block known bad actors by IP address or CIDR range:

  • Block individual IPs (e.g., 192.168.1.100)
  • Block entire subnets (e.g., 10.0.0.0/8)
  • Add a reason for each rule for audit purposes
  • Blocked requests receive a 403 Forbidden response

Allow rules

Not enforced in v0.1.0-beta.56. An Allow rule is saved and listed, but it has no effect on traffic.

Configuring IP Rules

  1. Go to Settings → Security → IP Access Control
  2. Click Add Rule
  3. Enter the IP address or CIDR range
  4. Select Block
  5. Optionally add a reason
  6. Save -- the proxy picks the rule up within about 30 seconds, when it next refreshes its list

Via API

# Block an IP
curl -X POST ".../api/ip-access-control" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "ip_address": "192.168.1.100",
    "action": "block",
    "reason": "Suspicious activity"
  }'

# Check if an IP is blocked
curl ".../api/ip-access-control/check/192.168.1.100" \
  -H "Authorization: Bearer YOUR_TOKEN"

IP access control uses PostgreSQL's native inet type with the <<= operator for efficient CIDR matching. Both individual IPs and subnet ranges are supported in a single rule.


Vulnerability scanning

Trigger a vulnerability scan

  1. 1

    Go to Projects and select your project.

  2. 2

    Find the vulnerability scan results in the project overview.

  3. 3

    Scans run automatically daily at midnight UTC. To trigger one now, use the CLI command or API (there is no dashboard button for manual triggering).

    Checkpoint: Confirm a new scan appears with a total count and a breakdown by severity (critical, high, medium, low).

  4. 4

    Click into the scan to see individual CVEs with package names, installed versions, fixed versions, and CVSS scores.

Temps automatically scans your deployed Docker images for known vulnerabilities using Trivy, an open-source security scanner. Scans run daily at midnight UTC and can also be triggered manually.

What Gets Scanned

  • OS packages (Alpine, Debian, Ubuntu, etc.) -- detects CVEs in system libraries
  • Language packages (npm, pip, Go modules, etc.) -- detects CVEs in application dependencies
  • Container configuration -- checks for security misconfigurations

Severity Levels

  • Name
    Critical
    Description

    Vulnerabilities that are trivially exploitable with severe impact (e.g., remote code execution without authentication). Fix immediately.

  • Name
    High
    Description

    Serious vulnerabilities that are exploitable with significant impact. Fix as soon as possible.

  • Name
    Medium
    Description

    Vulnerabilities that require specific conditions to exploit or have limited impact. Plan to fix in the next release cycle.

  • Name
    Low
    Description

    Minor vulnerabilities with minimal impact or very difficult to exploit. Fix when convenient.

Viewing Scan Results

  1. Go to Projects and select your project
  2. Vulnerability scan results appear in the project overview
  3. Each scan shows total count and breakdown by severity (critical, high, medium, low)
  4. Click into a scan to see individual CVEs with package names, installed versions, fixed versions, and CVSS scores

Triggering a Manual Scan

# Via API
curl -X POST "https://your-temps-instance.com/api/projects/{project_id}/scans" \
  -H "Authorization: Bearer YOUR_TOKEN"

# View latest scan results
curl "https://your-temps-instance.com/api/projects/{project_id}/scans/latest" \
  -H "Authorization: Bearer YOUR_TOKEN"

# View vulnerabilities for a specific scan
curl "https://your-temps-instance.com/api/projects/{project_id}/scans/{scan_id}/vulnerabilities" \
  -H "Authorization: Bearer YOUR_TOKEN"

Vulnerability scanning requires Trivy to be available on the Temps server. Temps will automatically use it if installed. Install Trivy with: curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh


Configuration inheritance

Security headers can be set globally and per project. A project with its own security-headers setting uses it in full (including "off"); otherwise the global setting applies. Environment-level header settings are stored but ignored in v0.1.0-beta.56. The IP access list has a single instance-wide level. Attack mode resolves differently (an environment value overrides the project value); see Attack Mode.

Last updated

Was this page helpful?