Security Review
RemoteLLM is a development stack. It contains writable shells and agent state, so review exposure before using it on a shared host or LAN.
Quick Check
Run:
make security-review
The check renders the Compose config with browser and optional-agent profiles, then warns about common mistakes:
- placeholder credentials
- nginx bound to all interfaces
- Docker socket mounts
- missing
no-new-privilegessettings - missing
runscruntime on writable agent shell services - missing or loose WireGuard config permissions
Warnings need human review. A blocking error means the rendered stack
includes a risk that should not be accidental, such as a Docker socket
mount. TTYD_PASSWORD=change-me is also blocking because
ttyd starts with -W, which gives authenticated
browser-terminal users a writable live shell.
Security Properties by Agent
| Command | Isolation |
|---|---|
make agent |
Docker + gVisor runsc runtime |
make codex |
Docker + Codex built-in Linux sandboxing |
make claude |
Docker container isolation |
make up-ide browser terminal |
Docker + gVisor runsc runtime; ttyd is writable after
login |
Manual Checklist
- Keep
NGINX_BIND=127.0.0.1unless LAN exposure is intended. - Replace
CODE_SERVER_PASSWORD,TTYD_PASSWORD,LITELLM_MASTER_KEY,LITELLM_SALT_KEY,LITELLM_UI_PASSWORD, andLITELLM_DB_PASSWORDbefore exposing browser tools. - Create per-role virtual keys (
make litellm-keys) and setAGENT_VIRTUAL_KEY,HERMES_VIRTUAL_KEY,CLAUDE_VIRTUAL_KEYin.env. Agents should never holdLITELLM_MASTER_KEY. - Do not change
LITELLM_SALT_KEYafter first boot — it encrypts stored virtual keys. - Keep WireGuard config under
.local/volumes/wireguard/wg_confs/wg0.confwith0600permissions. - Keep model traffic routed through LiteLLM and
OLLAMA_PROXY; do not set global proxy variables in the agent shell unless intentionally routing all package-manager traffic through the VPN. - Do not mount
/var/run/docker.sockinto agent containers unless a task explicitly needs host Docker control. - Use
safe-npm-install,safe-pip-install, andsafe-package-checkbefore adding dependencies. - Pin optional agent CLI package specs before enabling Codex CLI or Claude Code builds.
- Review
.local/volumes/before backups or sharing; it may contain shell history, agent transcripts, credentials, and memory files. - Leave passwordless sudo limited to development shell containers.
Non-shell services should keep
no-new-privileges:true.
Sudo Policy
The agent and web-terminal containers grant
passwordless sudo to the agent user via
/etc/sudoers.d/agent. This is intentional: the container is
a development sandbox, and restricting sudo would break package installs
and common developer workflows without meaningful security
improvement.
The meaningful isolation boundary is the container wall, not the sudo
gate inside it. All other services (wireguard,
nginx, litellm, vpn-proxy) use
no-new-privileges: true and do not grant elevated
privileges.
If deploying on shared infrastructure where the agent container is accessed by untrusted users, reconsider this policy and replace passwordless sudo with explicit per-command entries or remove it entirely.