Security RBAC admin/user, JWT stateless CORS restrictif (gateway) Scan images (Trivy), secret scanning