Security
The security posture of the platform and the controls that protect your workloads — secrets, certificates, isolation and data protection.
6 articles
Data Protection and Residency
Data protection and residency on Bahriya: vault items are encrypted at rest, and container data is processed only in the regions you choose to deploy to.
3 minPrivate Networking
Private networking on Bahriya keeps each project isolated by default; network policies add explicit allow rules for ingress peers and egress destinations.
3 minSecrets and Vault Best Practices
Secrets and vault best practices for Bahriya: keep credentials out of images, inject values at runtime, rotate on a schedule, and apply least privilege.
3 minSecuring Your Container
Securing your container on Bahriya: build minimal images, run as non-root, keep secrets in the vault, add a health check, and gate the ingress.
3 minSecurity
Security on Bahriya: authentication, encrypted secrets, automatic TLS, project network isolation, role-based access control, and IP-based access rules.
2 minTLS and Certificates
TLS and certificates on Bahriya: automatic provisioning and renewal for default hostnames and custom domains, plus TLS bundles when you bring your own.
3 min