Hardening, management plane và safe defaults
Tomcat hardening bắt đầu bằng giảm exposed surface, current patch level và least privilege; không phải một danh sách header rời rạc.
Security
Installation surface
Loại manager, host-manager, docs, examples nếu không dùng. Chạy non-root user, chỉ write temp/log/work cần thiết, bảo vệ conf/secrets và dùng image/read-only filesystem phù hợp. Không expose shutdown/management ports.
Manager, JMX và Realms
Management plane cần network isolation, strong authentication/authorization, TLS và audit. Tách deploy credentials khỏi monitoring. JMX remote config sai có thể mở code/data access; prefer local/agent-controlled paths.
Request security
Đặt header/body/count/time limits thống nhất với proxy; safe error pages; encode access log để tránh injection và scrub credentials/session/query PII. Disable TRACE/listing/unused methods/features theo application contract.
Patch và verification
Inventory Tomcat/JDK/native library/version provenance, subscribe security advisories và test upgrade. Scan effective deployment surface, ports, permissions, TLS, default apps và negative requests; config file tồn tại không chứng minh runtime applied.