Coverage area · 7 checks

Infrastructure and server config security

Servers are increasingly defined in your repository: Terraform, Ansible, Helm, Dockerfiles and committed config files. OpenRouting reviews those definitions for host-level weaknesses before they are applied.

ansible/ssh.yml1- lineinfile:2 path: /etc/ssh/sshd_config3 line: "PermitRootLogin yes"Infrawhat this review answersRoot or password logins allowed?Debug or admin ports exposed?Is this config for production hosts?$ verdict REAL ISSUE$ fix keys only, no root login▍

Illustrative example of how a finding in this area is reviewed.

Why this area matters

Security misconfiguration is OWASP Top 10 A05 and one of the most common root causes in breach reports: SSH open to root with passwords, debug mode left on, admin consoles exposed, TLS verification disabled. When infrastructure is code, every one of those decisions is visible in a diff.

IaC scanners like Trivy and Checkov are thorough but literal — they flag a debug flag in a local-dev compose file the same as in production, and they don't know which values your team overrides at deploy time. The infrastructure review agent reads the context: which environment the file is for, whether a value is a placeholder, and what the safe default should be.

What goes wrong in real applications

  • Remote access misconfiguration

    Root login or password authentication over SSH, or admin interfaces bound to public addresses, turns a single leaked or guessed password into full host control.

  • Debug and development settings in production

    Debug modes, verbose error pages and test endpoints leak internals and sometimes allow code evaluation. They are often enabled for a quick fix and never turned off.

  • Disabled transport security

    TLS verification switched off or cleartext listeners left enabled let anyone on the path read or modify traffic between services.

  • Insecure defaults left unchanged

    Default credentials, permissive CORS and wide-open file permissions in templates are copied into every environment built from them.

Sample: the risky pattern and the fix

Riskyansible/roles/base/tasks/ssh.yml
- name: Configure sshd
  ansible.builtin.lineinfile:
    path: /etc/ssh/sshd_config
    regexp: "{{ item.re }}"
    line: "{{ item.line }}"
  loop:
    - { re: "^PermitRootLogin", line: "PermitRootLogin yes" }
    - { re: "^PasswordAuthentication", line: "PasswordAuthentication yes" }
Saferansible/roles/base/tasks/ssh.yml
- name: Configure sshd
  ansible.builtin.lineinfile:
    path: /etc/ssh/sshd_config
    regexp: "{{ item.re }}"
    line: "{{ item.line }}"
    validate: /usr/sbin/sshd -t -f %s
  loop:
    - { re: "^PermitRootLogin", line: "PermitRootLogin no" }
    - { re: "^PasswordAuthentication", line: "PasswordAuthentication no" }
    - { re: "^MaxAuthTries", line: "MaxAuthTries 3" }

The role lets anyone log in as root with a password, so one weak or reused password gives full control of every host it runs on. The fix requires key-based login as a named user, limits retries and validates the config before applying it, so a typo can't lock you out.

Illustrative code, simplified for clarity — not taken from a customer repository.

What OpenRouting checks in your repository

  • Terraform, Ansible, Helm, CloudFormation and docker-compose files (Trivy config / Checkov, then agent review)
  • Server config committed to the repo: sshd_config, nginx and Apache configs, systemd units
  • Debug flags, verbose errors, permissive CORS and disabled TLS verification
  • Default or placeholder credentials in templates and environment files
  • Whether a file targets local development, CI or production (the main false-positive signal)

Scope and limits

  • It reviews the definitions in your repository, not running hosts — it doesn't log in to servers, run benchmarks or scan ports.
  • Settings applied by hand or by tooling outside the repository won't be seen, and drift between code and reality isn't detected.

Coverage areas reflect OpenRouting's check library. Code, secret and infrastructure scanning run today; other areas are rolling out. Scanners surface candidates and a review agent decides whether each one is real — it doesn't promise to find every issue.

Review agents for this area

Common questions

Does OpenRouting run Ansible or Terraform plans?

No. It never executes repository code, including IaC. It parses and reviews the files as committed.

Will it flag debug settings in my local docker-compose file?

Trivy or Checkov may. The infrastructure agent checks whether the file is scoped to local development or test and marks those findings as likely false positives with the reason.