Files
Garry TanandClaude Fable 5 be3f9c2159 docs(security): Docker network isolation for co-located self-hosted Postgres (#3270)
OAuth/source scoping only guards the serve --http path; a container
sharing Docker's default bridge with the brain's Postgres can open a
direct DB session without a token. Adds a 'Co-located Docker workloads'
subsection to docs/mcp/DEPLOY.md with the operator checklist, a
trust-boundary paragraph in SECURITY.md, and an ops note + cross-link
in the company-brain tutorial.

Fixes #3270

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 15:38:30 -07:00
..