Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Secure a Buttons deployment
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Map identity claims to roles
Next
Integrations →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Security/Secure a Buttons deployment

Secure a Buttons deployment

Buttons controls real broadcast infrastructure, so its own security matters as much as anything it's connected to. This is a task-oriented overview: it doesn't repeat the detail already covered in each linked guide, it tells you what to do and in what order, and calls out where the advice changes depending on how exposed your deployment actually is.

Start here: how exposed is this deployment?#

The right baseline depends on who can reach Buttons over the network, not just who's supposed to:
  • Local-only (a single machine, no network exposure beyond localhost): the lightest baseline. Strong accounts and a good backup plan still matter, but network-facing hardening is less urgent.
  • LAN (reachable from a studio or building network, not the public internet): add real TLS and locked-down account access, since anyone on that network is a potential reader or attacker if a account is weak or a certificate is skipped.
  • Externally managed (behind a load balancer, reverse proxy, or Kubernetes ingress, or otherwise reachable beyond your own network): treat certificates, API keys, and account access as if a stranger will eventually try them, because eventually one will.

Accounts and access#

  1. Give every person their own user account rather than sharing credentials. See Create and manage users.
  2. Build roles around what each job actually needs, not blanket access. See Create roles and assign permissions.
  3. If you're running a multi-node deployment or need to see who's actively signed in, review Understand and manage sessions: note this page is off by default and may not be enabled for your deployment.
  4. For surface-based sign-in, PIN and NFC are convenient but should still be treated as credentials. See Set up PIN and NFC sign-in. Repeated wrong passwords, PINs, or LDAP credentials on the same account are throttled automatically: after a few free wrong attempts (5 for passwords and LDAP, 3 for PINs), each further wrong attempt doubles the wait before the next check, starting at one second and capped at 2 minutes. A correct attempt clears the history. This needs no configuration, and because the wait never exceeds 2 minutes, someone typing wrong passwords can't lock the real owner out of their account.
  5. Protect the System Administrator account specifically: it can't be deleted, and if its password is lost, recovery goes through the watchdog application on the host machine, not the web interface (covered in Create and manage users).
  6. Bind connection credentials to a secret rather than leaving them as plain configuration text, and know that deleting a secret isn't blocked even while something still depends on it. See Store and rotate connection secrets.
  7. If you're connecting an enterprise identity provider, bring it online in the safe order: verify it with a real sign-in before switching anyone over to it by default. See Get started with SSO. Local sign-in is never disabled by SSO configuration, but keep a working local administrator account available regardless.

Network and transport#

  1. Know exactly which ports need to be reachable, from where, before you open anything. See the Network ports reference. Widening the editor's listen address beyond localhost is a deliberate choice, not a default.
  2. Replace the automatically generated self-signed certificate with one from a trusted authority once you're reachable beyond localhost. See Replace the HTTPS certificate. Plan the certificate's hostname coverage before you're mid-incident and need it to already be right.
  3. If Buttons runs behind Kubernetes or another externally managed certificate system, confirm that system (not this page) is what's actually renewing and rotating the certificate.
  4. For remote-execution connections like Bitfocus Listener, keep the credential hidden with a secret binding and scope which actions the remote side will actually run. See Connect to Bitfocus Listener.

API access#

  1. Confirm which interface an integration should actually use. See Choose how another system operates Buttons.
  2. Give every integration its own scoped key rather than a shared one, and grant only the permissions it actually uses. See Get started with the Control API.
  3. Set a rate limit appropriate to your real traffic, and monitor the request log for anything unexpected. See Secure and monitor the Control API.
  4. Revoke a key immediately if you suspect it's been exposed: revocation is immediate and can't be undone, which is the point.

Backups and recovery#

  1. Set up at least one scheduled backup rule so a recent, working configuration always exists. See Configure and monitor scheduled backups.
  2. Know how to export or import configuration manually for one-off moves, and understand exactly what an export does and doesn't protect. See Export or import Buttons configuration.
  3. Know the actual restore path and its automatic-rollback guarantee before you need it under pressure. See Restore and verify a backup.
  4. Treat every exported archive as sensitive: it can include connection configuration and license data even when secrets are excluded.

Ongoing health#

Keep an eye on service health so a stuck process doesn't quietly stay stuck. See Interpret system health and restart services safely. If you ever need to hand evidence to support without giving them remote access, see Collect logs and support evidence.

If you get stuck#

What you see
What to try
You're not sure where to start.
Work through this page in order: accounts, then network/transport, then API access, then backups. Each links to the detailed guide you need.
You don't know how exposed your deployment actually is.
If in doubt, treat it as LAN-exposed at minimum: the cost of a real certificate and locked-down accounts is low compared to the cost of skipping them.
You're not sure SSO is safe to turn on.
It is: local sign-in can't be disabled by SSO configuration. See Get started with SSO for the safe rollout order regardless.

Where to go next#

  • Settings overview, for the full list of Settings pages this guide draws from.

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful