jaque authenticates exactly one thing: the RPCs that change state, when -api-token is set. Every other surface, the dashboard, the read API, /metrics, Livestatus and the external command FIFO, is open to whatever can reach it, and secrets arrive as flags or environment variables that anything inspecting the process can read. This is pre-alpha software and the posture is stated rather than hidden: the network a jaque process listens on is the perimeter, and a reverse proxy is where TLS and authentication happen. Read this page before deciding which network a jaque process is allowed to sit on.

Status: there is no whole-system authentication story and no TLS in the binary. The gap is architectural, not a missing flag, and it changes as the project matures. See project status.

1. The one thing that is authenticated

-api-token puts a bearer-token check in front of CommandService only: the RPCs that change state, ProcessCheckResult, AcknowledgeProblem, ScheduleDowntime and the rest of the write surface. With it set, every command call needs a matching Authorization: Bearer <token> header, compared in constant time. Left empty, the default, the command API is open.

2. Everything else is unauthenticated by design

QueryService, the read API behind the dashboard and any external tooling, carries no interceptor regardless of -api-token. It serves projected, already-public monitoring state, so reads are always open.

/metrics and /status.json are unauthenticated HTTP endpoints on the same listener as the dashboard.

The dashboard itself (/) requires no login.

Livestatus (-livestatus-listen and -livestatus-socket) has no authentication at all. Anything that can open the TCP address or the UNIX socket can query it. This is the protocol as Nagios, Thruk and NagVis already use it; jaque adds nothing to it in either direction.

The external command FIFO (-command-file) is created mode 0660, inherited unchanged from Nagios. File permissions and group ownership are the entire access-control story, and anyone able to write the file can drive jaque's state.

Notification adapter secrets, -smtp-pass, -telegram-token and the rest, arrive via flags or their JAQUE_-prefixed env vars. They are visible to anything that can read the process's environment or command line: /proc/<pid>/environ, ps, a container platform's own env inspection. jaque does not fetch them from a secret store.

3. The stated posture

Put a reverse proxy in front of anything exposed beyond localhost and terminate TLS, authentication and network exposure there; jaque itself does not do TLS. Treat the network a jaque process listens on as the perimeter: -listen, -livestatus-listen and the FIFO's containing directory all sit behind whatever boundary (firewall, private subnet, UNIX socket permissions) keeps untrusted clients out, because jaque will not turn them away itself.

None of the above is a gap to be filed as a bug against a specific endpoint. It is the current shape of the trust model.

4. Security considerations

This page is the security considerations section for the deployment chapter. The pages that open a listener or handle a secret (Topologies, Cluster and coordination, Kubernetes, Docker) each end by pointing back here.