Hardening

The admin account, the database, expressions, job data, optional features and role options

  1. The admin account
  2. The database
  3. Expressions and outbound calls
  4. Job data
  5. The settings pages and the designer
  6. Optional features
  7. Role options

The admin account

The local admin account is created at first start from ADMIN_USERNAME and ADMIN_PASSWORD, whose default is AnsibleForms!123.

  • Change the password on the Users page; ADMIN_PASSWORD is only read when the account is first created.
  • REINIT_ADMIN=1 resets the password to ADMIN_PASSWORD at every start. Use it only to recover a lost password, then unset it and restart.
  • Set the two master secrets first: see Secrets and encryption.
  • Once LDAP or OAuth2 sign-in works, keep the local admin for emergencies only, with a long password stored in your vault.

The database

AnsibleForms holds every credential and job in its MySQL database, so keep that database off the network:

  • The docker-compose project publishes MySQL on the host (MYSQLDB_LOCAL_PORT, 3306) and ships with the root password AnsibleForms!123. Remove that port mapping, or bind it to 127.0.0.1, and change the password.
  • Connect with a dedicated account rather than root where your setup allows it: DB_USER and DB_PASSWORD.
  • Set ALLOW_SCHEMA_CREATION to 0 once the schema exists. Creating the schema drops every table first; with 0 neither the startup bootstrap nor the /api/v2/schema endpoint can run it.

Expressions and outbound calls

Server expressions run on the server for any signed-in user, so the sanitizer and the outbound filters matter:

  • EXPRESSION_SANITIZER : strict or paranoid, never legacy, which lets users run server code.
  • REST_DENIED_HOSTS : hosts REST expressions may not reach, e.g. 169.254.169.254,127.0.0.0/8.
  • REST_ALLOWED_HOSTS : when set, REST expressions can reach only these hosts and ranges. The denied list wins over it.

Both lists only cover the REST helper functions of AnsibleForms itself; playbooks run outside them and are not filtered.


Job data

Job extravars and output are stored in the database and shown to everyone who can see the job:

  • MASK_EXTRAVARS_REGEX : extravars whose key matches are shown as ********. The default is password|secret|token; password fields are always masked. Extend it with the names your forms use, for example password|secret|token|apikey|passphrase.
  • EXTRAVARS_USER_FIELDS : trims the ansibleforms_user object sent with every job, which otherwise holds the user’s whole group membership.
  • REGEX_FILTER_JOB_OUTPUT only hides noisy tasks; hide secrets with no_log.

The settings pages and the designer

Administrators can change much of the configuration from the browser. Narrow that where the configuration lives elsewhere:


Optional features

These features are off by default. Switch them on only when you use them; each needs a restart:

  • ENABLE_MCP : serves the MCP server on /api/v2/mcp, so MCP clients can launch forms with a user’s token.
  • ENABLE_CHAT : the chat assistant. Form definitions and the values being filled in are sent to the configured model provider.

LAUNCH_VALIDATION works the other way round: it is off by default and worth switching on. With enforce, the server refuses a launch whose values break the form’s rules, including launches through the REST API. Start with log, see Launch validation.


Role options

Some role options in config.yaml give more than their name suggests. Grant them with care:

Option Why it matters
allowScheduledJobs A user with it sees and can change every schedule, and a schedule runs with admin rights, for any form. Treat it as admin-level.
allowBackupOps Includes restore, which replaces the whole database.
showSettings Opens the administration pages.
showLogs Shows the server log, which can contain host names, user names and error details.
showAllJobLogs Shows the jobs of every user, not only the user’s own.
extendedTokenExpiration Lets the user create long-lived API tokens, which cannot be revoked one by one.

When the admin role sets no options it has all of them; options on the public role apply to every user.