This document outlines security best practices for operating the PredictBot trading stack safely.
- Wallet Security
- API Key Management
- Environment Configuration
- Server Security
- Operational Security
- Incident Response
- Create a separate wallet specifically for PredictBot
- Only fund it with the amount you're willing to risk
- Never store more than your intended trading capital
- Created new wallet specifically for trading
- Backed up seed phrase securely (offline, encrypted)
- Funded with limited capital only
- Verified wallet address before depositing
- Tested with small transaction first
# NEVER do this:
POLY_PRIVATE_KEY=0x123... # In code or public files
# ALWAYS do this:
# Store in .env file with restricted permissions
chmod 600 .env| Risk Level | Funding Amount | Use Case |
|---|---|---|
| Testing | $50-100 | Initial testing, dry runs |
| Conservative | $200-500 | Low-risk strategies only |
| Moderate | $500-1000 | Full stack operation |
| Aggressive | $1000+ | Experienced users only |
- Generate unique keys for each application
- Use descriptive names (e.g., "PredictBot-Production")
- Set minimum permissions required
- Enable IP restrictions where available
- Set spending limits on AI APIs
| Key Type | Rotation Frequency | Notes |
|---|---|---|
| Exchange API Keys | Every 90 days | Or immediately if compromised |
| AI Service Keys | Every 90 days | Monitor usage for anomalies |
| RPC Endpoints | As needed | Rotate if rate limited |
# .env file permissions (Linux/Mac)
chmod 600 .env
chown $USER:$USER .env
# Verify permissions
ls -la .env
# Should show: -rw------- 1 user user ... .env- Immediately revoke the compromised key
- Generate new keys from the platform dashboard
- Update .env with new keys
- Restart services to load new keys
- Review logs for unauthorized activity
- Check account balances for unexpected changes
# Create .env from template
cp .env.template .env
# Set restrictive permissions
chmod 600 .env
# Verify it's in .gitignore
grep ".env" .gitignoreAdd to .gitignore:
.env
.env.*
*.pem
*.key
secrets/
Create .git/hooks/pre-commit:
#!/bin/bash
# Prevent committing secrets
# Check for private keys
if git diff --cached | grep -E "PRIVATE_KEY|API_KEY|API_SECRET" | grep -v "template\|example"; then
echo "ERROR: Potential secret detected in commit!"
echo "Please remove secrets before committing."
exit 1
fiAlways run validation before starting:
python scripts/validate_secrets.py --strict-
Update system packages
sudo apt update && sudo apt upgrade -y -
Configure firewall
# Allow SSH sudo ufw allow 22/tcp # Allow only necessary ports sudo ufw allow 8000/tcp # Kalshi AI dashboard (if needed) sudo ufw allow 8080/tcp # Orchestrator health check # Enable firewall sudo ufw enable
-
Disable root login
# Edit /etc/ssh/sshd_config PermitRootLogin no PasswordAuthentication no # Use SSH keys only
-
Use SSH keys
# Generate key pair (on local machine) ssh-keygen -t ed25519 -C "predictbot-server" # Copy to server ssh-copy-id user@server
-
Don't run as root
# In Dockerfiles USER nonroot
-
Use read-only mounts where possible
volumes: - ./config:/app/config:ro # Read-only
-
Limit container resources
deploy: resources: limits: cpus: '1.0' memory: 512m
-
Use specific image tags
FROM python:3.12-slim # Not python:latest
- Use internal Docker network for inter-service communication
- Expose only necessary ports to host
- Use HTTPS for any external dashboards
- Consider VPN for remote access
ALWAYS start with DRY_RUN=1
# In .env
DRY_RUN=1
# Verify in logs
docker-compose logs | grep -i "dry.run"- Phase 1: Run with DRY_RUN=1 for 24-48 hours
- Phase 2: Enable one strategy with minimal capital
- Phase 3: Gradually increase capital and enable more strategies
- Phase 4: Full deployment with monitoring
- Check logs daily for errors
- Monitor wallet/account balances
- Review trade history for anomalies
- Check API usage and costs
- Verify circuit breakers are working
Set conservative limits initially:
# config.yml
risk_management:
global:
max_daily_loss: 50.0 # Start low
max_total_position: 500.0 # Half of bankroll-
Configuration backups
# Backup config (without secrets) cp config/config.yml config/config.yml.backup -
Database backups
# Backup SQLite databases docker cp predictbot-kalshi-ai:/app/data/kalshi_ai.db ./backups/ -
Log retention
- Keep logs for at least 30 days
- Archive important logs monthly
- Unexpected trades or positions
- API rate limit errors (someone else using keys)
- Unusual login notifications from platforms
- Wallet balance changes you didn't make
- High AI API costs
-
Stop all trading
docker-compose down
-
Revoke all API keys from platform dashboards
-
Check account balances on all platforms
-
Review logs for unauthorized activity
docker-compose logs > incident_logs.txt -
Transfer funds from trading wallet if needed
-
Generate new keys and update configuration
-
Investigate how compromise occurred
-
Document the incident
Keep these handy:
- Kalshi support: support@kalshi.com
- Polymarket Discord: [link]
- Your exchange's emergency contact
- All old keys revoked
- New keys generated and tested
- Logs reviewed and archived
- Root cause identified
- Security improvements implemented
- Incident documented
- Created dedicated trading wallet
- Funded wallet with limited capital
- Generated all API keys
- Created .env file with correct permissions
- Verified .env is in .gitignore
- Ran secrets validation script
- Set DRY_RUN=1
- Configured conservative risk limits
- Review logs weekly
- Check API key expiration
- Monitor account balances
- Update system packages monthly
- Rotate keys quarterly
- Backup configurations
- Tested thoroughly in dry-run mode
- Verified all circuit breakers work
- Set appropriate position limits
- Configured alerts/notifications
- Documented emergency procedures
- Have incident response plan ready