agentsclimarketplace

Couchbase security hardening

Skill celticht32/Couchbase-Skills-for-Claude.ai/skills/couchbase/couchbase-security-hardening

This is a collection of skills I have created for Couchbase for Claude.ai

Install
npx -y skills add celticht32/Couchbase-Skills-for-Claude.ai --skill couchbase-security-hardening

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 4 stars4 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Harden and audit Couchbase security posture for production deployments. Use whenever the user asks about TLS configuration, mTLS, certificate management, LDAP integration, SAML, PAM authentication, audit logging, audit log configuration, network isolation, firewall rules for Couchbase, RBAC design, least-privilege, password policy, account lockout (8.x), encryption at rest (DARE), KMIP key management, compliance (SOC2, HIPAA, PCI-DSS, FedRAMP), security hardening checklist, admin_encryption_*, admin_kmip_*, or 'how do I secure Couchbase for production.' Distinct from couchbase-mcp (calling the tools) and couchbase-app-integration (TLS in SDK clients). Use proactively for new production deployments, compliance reviews, security audits, and pre-certification hardening.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

5.0 KB, as published. Nobody here has run it

Couchbase Security Hardening

A skill for hardening Couchbase deployments — TLS, RBAC, audit logging, encryption at rest, external authentication, network isolation, and compliance alignment.

Distinct from:

  • couchbase-mcp — calling the security tools (admin_user_*, admin_encryption_*, etc.)
  • couchbase-app-integration — TLS/mTLS configuration in SDK client code

When this skill applies

  • "How do I secure Couchbase for production?"
  • "How do I set up TLS / enforce TLS-only connections?"
  • "How do I integrate Couchbase with LDAP / Active Directory?"
  • "How do I design RBAC for my team?"
  • "What audit logging should I enable?"
  • "How do I enable encryption at rest (DARE)?"
  • "What's KMIP and when do I need it?"
  • "How do I harden Couchbase for SOC2 / HIPAA / PCI?"
  • "How do I configure password policy and account lockout?"

Pick the right reference

QuestionRead
"TLS — enabling, certificate rotation, enforcing TLS-only, mTLS"references/tls.md
"RBAC — role design, least-privilege, service accounts, group structure"references/rbac.md
"External auth — LDAP, Active Directory, SAML, PAM"references/external-auth.md
"Audit logging — what to enable, log rotation, SIEM integration"references/audit-logging.md
"Encryption at rest — DARE, KMIP, key rotation"references/encryption-at-rest.md
"Network hardening — ports, firewall rules, node-to-node TLS"references/network-hardening.md

Security hardening checklist

Before going to production, verify all of these:

Authentication & access:

  • Default Administrator password changed from the default
  • All application connections use dedicated service accounts (not Administrator)
  • All service accounts have minimum required roles only
  • RBAC groups defined so roles are assigned via group, not per-user
  • Password policy configured (min length ≥ 12, complexity, rotation)
  • Account lockout enabled (8.x: admin_user_lockout_settings)
  • External auth (LDAP/AD) configured if your organization requires centralized identity

Network & encryption:

  • TLS enabled and TLS 1.2+ enforced (TLS 1.0 / 1.1 disabled)
  • Node-to-node encryption enabled (cluster internal traffic)
  • All client SDK connections use couchbases:// (TLS)
  • Ports restricted to Couchbase service ports only (see network-hardening.md)
  • Cluster nodes on a private network, not directly internet-accessible
  • Capella: allowed CIDRs configured; no 0.0.0.0/0

Data protection:

  • Encryption at rest (DARE) enabled if required by compliance
  • KMIP configured if your org requires external key management
  • Backup encryption enabled (cbbackupmgr --encrypted)

Audit & visibility:

  • Audit logging enabled
  • admin_loggedIn and admin_loggedOut events captured
  • mutateDocument events captured for sensitive collections
  • Audit log rotation and retention configured
  • Audit logs shipped to SIEM

Quick tool map

TaskTool
Get current security settingsadmin_cluster_get_security_settings
Update security settings (TLS, sessions)admin_cluster_update_security_settings
Configure password policyadmin_cluster_set_password_policy
Get/update auto-failover (security adjacent)admin_cluster_get_auto_failover_settings
User managementadmin_user_*
Group managementadmin_group_*
List rolesadmin_user_list_roles
Check current user permissionsadmin_user_check_permissions
Encryption settings (DARE)admin_encryption_get_settings, admin_encryption_update_settings
KMIP configurationadmin_kmip_*
Audit log configurationadmin_cluster_get_audit_config, admin_cluster_update_audit_config
User lockout (8.x)admin_user_lock, admin_user_unlock, admin_user_get_lockout_settings

Related skills

  • couchbase-mcp — the actual security tools
  • couchbase-app-integration — TLS/mTLS configuration in application SDK clients
  • couchbase-observability — shipping audit logs and security metrics to monitoring systems
  • couchbase-backup-restore — backup encryption configuration

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.