Skip to content

Security: lite-tx/StreamForge

Security

SECURITY.md

Security policy

Supported configuration

StreamForge's local Compose profile is a development and acceptance environment. It binds RTMP, playback/media HTTP, RTSP, and the product API to 127.0.0.1 by default. ZLMediaKit's REST routes share its HTTP playback listener, so they are also reachable through the bound media HTTP port; an independent ZLM_API_SECRET protects them, but that is not network isolation.

Before any non-local deployment:

  • replace every value from .env.example with generated secrets;
  • terminate TLS at a reviewed reverse proxy;
  • expose only required playback paths through that proxy and keep ZLMediaKit management routes behind a firewall or private network;
  • restrict ingress to the publisher, player, and operator surfaces actually used;
  • store operator and channel credentials in a secret manager;
  • disable API debug output and review log redaction;
  • rotate credentials and export the bounded local event journal externally before its configured retention window advances;
  • set host-level filesystem quotas when the 10 GiB/24-hour recording janitor is not a sufficient hard storage boundary for the expected bitrate;
  • review the enabled protocol and codec attack surface;
  • complete a dependency and license scan of the exact built images.

Local resource boundaries

The Compose profile applies explicit memory, CPU, PID, and file-descriptor limits to its services. The control API rejects malformed HTTP body framing and bodies larger than 65,536 bytes before FastAPI route parsing. The body is kept in one bounded buffer with a five-second total upload deadline; Uvicorn also caps concurrent requests. Producer event details are a strict, flat schema matching the bundled OBS adapter, with bounded counters and text fields.

SQLite keeps 10,000 events by default. Each channel has a 64-item pending FIFO, a 10,000-key active idempotency quota with a 24-hour replay window, and a separate cap for terminal commands not referenced by a live replay mapping. Pending work and referenced command outcomes are never removed by history pruning. New work above an admission quota receives HTTP 429 and the surrounding state/command transaction is rolled back.

ZLMediaKit writes five-minute MP4 segments to a named volume. A separate networkless, non-root pruner deletes finalized, non-hidden MP4 files after 24 hours or when their aggregate size exceeds 10 GiB, oldest first. It never deletes the dot-prefixed file ZLMediaKit is still writing. This is lifecycle retention, not a portable filesystem quota: one active segment, Docker metadata, or another writer can still exceed it, so production operators must enforce a host/storage quota where disk exhaustion is a hard risk.

Reporting

Do not include live credentials, publish keys, media URLs containing tokens, or recorded user content in a public report. Provide a minimal reproducer and the affected StreamForge commit through the repository owner's private contact path.

There aren't any published security advisories