Secure app development¶
The principles, prerequisites and requirements for IE app development can be found online here.
Further information on how to develop apps and how to load them to the IEM or to the IE Hub can be found in these documents:
- Industrial Edge App Publisher – Operation
- Industrial Edge - Publishing Apps to the IE Hub
Docker security policies¶
Industrial Edge relies on default Docker security configuration to restrict app permissions.
Apps can request additional permissions and capabilities in the app metadata. This is displayed upon installation, so the operator can accept these permissions or reject the installation of the app.
Usage of trustworthy Docker images¶
Customers are responsible for the content and security of their apps. Furthermore, customers are responsible for using only trustworthy Docker images from a trustworthy Docker registry respectively from trusted resources for their own apps and check them accordingly. Customers also must ensure to deliver security patches in a certain time.