[OneDev #10] feat(security): establish red/blue team security cycle for PCT infra #31

Open
opened 2026-05-24 04:46:40 +00:00 by joseph · 0 comments
Owner

Imported from OneDev issue #10 (id 35250)
Original project: internal-joseph
Original state: Open
Original submitterId: 5
Original submitDate: 2026-04-09T17:04:08.830+00:00
Original lastActivity: {'date': '2026-04-09T17:04:08.830+00:00', 'description': 'opened', 'userId': 5}

Original fields:

  • Type: New Feature
  • Priority: Normal
  • Assignees: None

Idea

Implement a recurring red-vs-blue security cycle for PCT's own infrastructure. Red phase: simulate attacks against exposed surfaces (Caddy reverse proxy, Dex SSO, OneDev, sshubble, LXC/VM guest escapes, WireGuard endpoints, pctbin.com). Blue phase: harden, patch, and improve detection based on findings. Rotate between phases on a defined cadence (monthly or quarterly).

Why

PCT's infra has grown significantly — 30+ VMs/LXCs, multiple public endpoints, SSO, secrets API, RDP/SSH access. No structured security review exists. A red/blue cycle builds institutional knowledge of the attack surface, catches drift between deployments, and keeps both offensive and defensive skills sharp. Findings feed directly into hardening tasks and runbook updates.

Open questions

  • Solo or bring in a second person for the red team phase?
  • Scope boundary: PCT infra only, or also simulate attacks on client-facing tooling (sshubble agent, m365-tool)?
  • Output format: issue-per-finding, or a structured report per cycle?
Imported from OneDev issue #10 (id 35250) Original project: internal-joseph Original state: Open Original submitterId: 5 Original submitDate: 2026-04-09T17:04:08.830+00:00 Original lastActivity: {'date': '2026-04-09T17:04:08.830+00:00', 'description': 'opened', 'userId': 5} Original fields: - Type: New Feature - Priority: Normal - Assignees: None ## Idea Implement a recurring red-vs-blue security cycle for PCT's own infrastructure. Red phase: simulate attacks against exposed surfaces (Caddy reverse proxy, Dex SSO, OneDev, sshubble, LXC/VM guest escapes, WireGuard endpoints, pctbin.com). Blue phase: harden, patch, and improve detection based on findings. Rotate between phases on a defined cadence (monthly or quarterly). ## Why PCT's infra has grown significantly — 30+ VMs/LXCs, multiple public endpoints, SSO, secrets API, RDP/SSH access. No structured security review exists. A red/blue cycle builds institutional knowledge of the attack surface, catches drift between deployments, and keeps both offensive and defensive skills sharp. Findings feed directly into hardening tasks and runbook updates. ## Open questions - Solo or bring in a second person for the red team phase? - Scope boundary: PCT infra only, or also simulate attacks on client-facing tooling (sshubble agent, m365-tool)? - Output format: issue-per-finding, or a structured report per cycle?
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
joseph/internal-joseph#31
No description provided.