doc/administration/geo/replication/security_review.md
{{< details >}}
{{< /details >}}
The following security review of the Geo feature set focuses on security aspects of the feature as they apply to customers running their own GitLab instances. The review questions are based in part on the OWASP Application Security Verification Standard Project from owasp.org.
admin: true is set in the database is
considered an administrator with super-user privileges.Whether to use these is to be decided by our customers, according to their operational needs:
db_key_base) which is used to decrypt certain columns in the database.
The db_key_base secret is stored unencrypted on the file system, in
/etc/gitlab/gitlab-secrets.json, along with a number of other secrets. There is
no at-rest protection for them.gitlab-ctl set-primary-node).git clone operations initiated by the end-user.db_otp_key.http: and https:.)