From aff6188388bb22ad7f6eb490a92d7c3a778e82b4 Mon Sep 17 00:00:00 2001 From: Copple <10214025+kiwicopple@users.noreply.github.com> Date: Wed, 12 Jan 2022 09:31:21 +0100 Subject: [PATCH] adds a note about security --- web/docs/guides/hosting/docker.mdx | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/web/docs/guides/hosting/docker.mdx b/web/docs/guides/hosting/docker.mdx index 838753ab0c8..013cc6f4384 100644 --- a/web/docs/guides/hosting/docker.mdx +++ b/web/docs/guides/hosting/docker.mdx @@ -64,6 +64,11 @@ Update the `.env` file with your own secrets. In particular, these are required: - `SITE_URL`: the base URL of your site. - `SMTP_*`: mail server credentials. You can use any SMTP server. + +### Securing the Dashboard + +The Docker setup doesn't include a management database for managing users and logins. If you plan to deploy the Studio to the web we suggest you put it behind a web proxy with Basic Auth or hide it behind a VPN. + ## Configuration To keep the setup simple, we made some choices that may not be optimal for production: