Infrastructure credentials
The default configuration ships with weak, well-known passwords for PostgreSQL, MinIO, and Redis. Replace them with strong, unique values before exposing Tracecat to production traffic.command override in your docker-compose.yml:
Platform secrets
Tracecat requires four cryptographic secrets, plus an optional keyring if you enable Temporal payload encryption.
Tracecat requires four secrets. Generate them with
openssl:
Temporal payload keyring
TEMPORAL__PAYLOAD_ENCRYPTION_KEYRING holds a JSON keyring rather than a single key. Each entry maps a key ID to a root secret, and current_key_id selects the key that encrypts new payloads:
TEMPORAL__PAYLOAD_ENCRYPTION_KEYRING_ARN instead, and Tracecat fetches the keyring from Secrets Manager at runtime.
Where to store them
Keep these out of your application configuration and out of version control. Use the mechanism your platform already provides.
On Kubernetes, prefer External Secrets Operator over a hand-created Secret. Your secret manager stays the source of truth, the operator re-syncs values rather than copying them, and no plaintext passes through a shell history or a manifest. Reserve chart-managed secret templates for pipelines that encrypt values at rest with Sealed Secrets or SOPS.
Rotation
Rotation support differs by secret. Check the differences before you plan a rotation window.Isolation
Tracecat executes user-defined Python scripts, custom actions, and agents inside the executor service. You choose between nsjail isolation and no isolation. Defaults differ by deployment target.nsjail sandbox (recommended for production)
For production, enable nsjail — a process isolation tool from Google that enforces:- Filesystem isolation — scripts reach only their job directory and explicitly mounted paths. The host filesystem stays invisible.
- Resource limits — nsjail caps CPU time, memory, file size, and process count per execution, so a runaway script cannot starve the host.
- User namespace separation — scripts run as unprivileged users even when the container runs as root.
- Network access — scripts keep network access, since they need to reach databases, APIs, and S3, but nsjail confines it to the container’s network namespace.
.env:
ephemeral value remains an alias for nsjail.
nsjail requires:
- Linux with kernel 4.6+
- Docker privileged mode or
CAP_SYS_ADMINcapability on the executor container - The nsjail binary and sandbox rootfs (included in Tracecat images)
nsjail is not supported on macOS or Windows. Use the
direct backend on those platforms.Resource limits
When you enable nsjail, agent sandboxes get a cgroup v2 memory budget shared by their child processes. Python scripts and custom actions use a per-process virtual address-space cap.
Pass
TRACECAT__SANDBOX_DEFAULT_MEMORY_MB to your action executor and TRACECAT__AGENT_SANDBOX_MEMORY_MB to agent-executor. Docker Compose forwards the agent settings; Kubernetes deployments must add them to the agent executor container.
Agent sandboxes also have a per-process address-space guard (rlimit_as), defaulting to twice the memory budget: 8192 MiB with the default 4096 MiB budget. Set TRACECAT__AGENT_SANDBOX_ADDRESS_SPACE_MB=16384 to override it with 16 GiB. Size this guard above your workload’s peak virtual size, since runtimes can reserve address space before using RAM. Stdio MCP connection probes use the same policy with a memory budget capped at 1024 MiB.
Agent nsjail requires a writable cgroup v2 subtree with the memory controller enabled. The Compose sandbox overlay starts python -m tracecat.agent.sandbox.cgroup as root to prepare the container’s subtree, then drops privileges to apiuser before starting the worker. Other deployments must use that bootstrap with an isolated, writable container cgroup namespace, or delegate a subtree and set TRACECAT__AGENT_SANDBOX_CGROUP_PATH=/sys/fs/cgroup/agent-sandboxes. The worker rejects missing delegation before accepting activities.
Set concurrency so all sandbox budgets plus worker overhead fit within the outer container limit. Tracecat does not resize concurrency automatically. A per-sandbox limit cannot prevent a container OOM when the sum of concurrent workloads exceeds that outer limit.
For Python scripts and custom actions, the memory setting still controls rlimit_as per process. Python can raise MemoryError at this limit; native runtimes can abort.
Tracecat reports an action or agent run that exceeds the memory, CPU time, or file size limit as sandbox.resource_limit_exceeded. The failure is attributed to the workload, is not retried, and the error names the env var that controls the cap.
Two limits fall outside that guarantee. Exceeding the process count fails process creation inside the sandbox with an ordinary error instead of killing the workload, so it surfaces as whatever the script or agent does with that error. Dependency installation is reported as a package installation failure whichever limit it hits.
These limits apply only when nsjail is enabled. Without it Tracecat installs no rlimits, so a failure of the same shape is reported as an ordinary workload or platform failure.
No isolation
Without nsjail, scripts, custom actions, and agents run as regular subprocesses in the executor. This is a supported production configuration when you trust everything that runs. That means your own workflow and custom registry code, the third-party dependencies those actions install, and the agents, tools, and MCP servers you enable. Review that code and pin those dependencies as you would any code with direct access to your systems. Choose nsjail instead when you run code you have not reviewed, such as untrusted third-party packages or agents that generate and execute their own code.Choosing a backend
Authentication
Docker Compose deployments default to basic email/password authentication. For production, configure OIDC or SAML SSO. See Roles and permissions for the roles you assign to users and groups once they can sign in.TLS
Never run production traffic over plain HTTP. See TLS and certificates for Caddy-based automatic TLS setup, custom certificates, and trusting internal CAs.Related pages
- See Architecture for the platform and AI agent trust model.