ΒΆ
Nebula Security Hardening
Protect CA key material offline; issue certs with short lifetimes.
Use strict firewall rules in Nebula host configs.
Rotate host certificates and revoke compromised identities quickly.
Restrict lighthouse exposure and monitor handshake failures.