Security Model
How QuickStack isolates workloads and controls access: deny-by-default networking, RBAC, authentication, TLS, and data residency.
This page summarizes the security model so operators and compliance reviewers can see what is controlled where.
Network isolation
Apps cannot talk to each other or to the internet by default. Traffic is allowed only through explicit network policy rules that you create, which makes QuickStack secure by default.
- Ingress and egress rules are per app and per port, with
TCPorUDP. - Rules are bidirectional: adding a rule from one side creates the matching rule on the other.
- Each app has a separate Internet Access egress switch.
- Databases created from templates deny internet access automatically.
See Networking & Policies for the full model.
Access control
QuickStack organizes access with users, groups, and permissions:
- Permissions are granted per project, with optional per-app overrides.
- Permission levels are Read Apps, Write Apps, Create Apps, and Delete Apps.
- The built-in Admin group has full access and cannot be modified.
- API keys inherit the permissions of the user that created them.
See Users & Groups.
Authentication
- Local accounts — email and password.
- Two-factor authentication (TOTP) — per account. See 2FA.
- Single sign-on — OIDC, Google, Microsoft Entra ID, and GitHub. SSO can link to existing accounts by verified email. See Single Sign-On.
- REST API keys — scoped to a user, with optional expiry. See Authentication.
Transport and certificates
Traefik terminates TLS for apps and the QuickStack UI and provisions Let's Encrypt certificates automatically. HTTP Basic Authentication can add a password prompt in front of any app at the proxy level. See Custom Domains and Basic Authentication.
Basic Auth is not a replacement for application auth Credentials are sent as Base64 on every request. Always use HTTPS, and keep application-level authentication for sensitive data.
Data residency and privacy
QuickStack is fully self-hosted. Application data, volumes, backups, and the configuration database stay on infrastructure you control. There is no third-party analytics or tracking SDK in the product.
Current limitations relevant to compliance reviews:
- No user audit log (login history, change history) is implemented. Deployment and build logs are available per workload.
- There is no built-in real-time telemetry or alerting integration.
Backup and recovery
- Volume and database backups go to S3-compatible storage you configure. See Backups Overview.
- System backups capture the QuickStack configuration (projects, users, secrets) and can be downloaded and restored from the UI. See System Backups.
- Volume and database backups can be downloaded but currently have no in-UI restore action. See Download & Restore.
License and source
QuickStack is open source under the GPL-3.0 license. The source is on GitHub; you can audit it, self-host it, and migrate away at any time.
Related
Projects, Apps & Databases
Understand the QuickStack object model: projects, apps, databases, Agent Sandboxes, sources, deployment state, and where each setting lives.
Project Canvas & App Drawer
Use the Project Canvas to see apps, databases, and connections at a glance, and create, configure, deploy, and monitor every app from its details drawer.