Security
Shared hardware, clear rules
A test lab that is reachable remotely must be secure by default. NablaBox has security built into the product rather than bolted on.
Remote access uses an outbound NetBird (WireGuard) connection. The REST API listens on the local interface only until an administrator explicitly enables external access.
Three roles – admin, user and read-only reporter – plus per-DUT assignments: a user can only operate the DUTs they have been assigned to. Users can deposit their own SSH keys for device access.
Every API request is logged with source address, user, action and result – including requests that were rejected.
Passwords are stored as Argon2 hashes, sessions use signed tokens, and secrets such as the VPN setup key are encrypted at rest.
A/B updates with SWUpdate: an update is either applied completely or not at all, and the previous system stays available as a fallback.
NablaBox is developed with the EU Cyber Resilience Act in mind. A documented cybersecurity risk analysis is maintained alongside the product.