Skip to main content

Identity and access

  • Require phishing-resistant passkeys or TOTP for operators.
  • Grant organization and project permissions independently.
  • Create one API key per workload and environment.
  • Disable or delete credentials when their owner or workload changes.
  • Keep API secrets in a server-side secret manager and prevent them from entering logs.

Cloud CDN

  • Use HTTPS to the origin and enable origin TLS validation.
  • Restrict direct origin access where your architecture permits it.
  • Do not publicly cache responses that vary by Authorization, cookies, or user identity.
  • Review custom cache keys and ignored query parameters for cross-tenant collisions.
  • Validate CORS, request headers, and response-header hiding policies in staging.
  • Treat signed-URL keys as secrets and rotate them through a controlled process.

Cloud DNS

  • Lower TTLs before a planned cutover, not during it.
  • Verify the complete record set before changing nameservers.
  • Preserve mail, verification, CAA, and delegation records during migration.
  • Use health checks only for endpoints whose failure behavior you have tested.
  • Confirm what happens when every eligible endpoint is unhealthy.

Incident response

If a credential may be compromised, disable the key or roll its secret, revoke human sessions, inspect recent changes and analytics, and contact support@aptranet.com. Include trace IDs but never include secrets.