SECURITY
Security considerations
PANTAW reduces operational risk through deterministic, read-only collection and explicit authorization boundaries.
Runtime account
Use a dedicated unprivileged Linux account. Grant only the procfs, sysfs, systemd-manager and device visibility required by selected collectors. Do not use unrestricted root.
Commands
The shared helper uses explicit argument vectors, shell=False, captured output, non-raising exit handling and mandatory finite timeouts. Collectors authorize only their documented fixed read-only commands.
Files and audit
Restrict configuration, SOP, state, log, SQLite and JSONL permissions. Avoid symlink ambiguity, keep secrets out of configuration, and protect audit data as operational inventory.
Public/private boundary
This portal contains static product information only. It cannot execute PANTAW, access node files, query private audit databases, read logs or control systemd.