flyio-security-basics
Installation
SKILL.md
Fly.io Identity, Secrets, and Network Baseline
Overview
Protect the control plane, deployed code, runtime secrets, images, network paths, and support evidence as one system. Scoped tokens reduce control-plane authority, but deploy access remains highly sensitive because new code can read secrets injected into Machines.
Prerequisites
- Human and workload identity inventory with owners and expiry policy
- Apps, process groups, images, domains, certificates, private peers, and data flows
- Incident, rotation, vulnerability, and access-review procedures
Instructions
Step 1: Separate identity classes
Distinguish interactive operators, app deploy automation, organization automation, read-only monitoring, SSH, Machine-exec, WireGuard, database, and external-service identities.