Public release release-98d969b26488
Source commit: 98d969b26488b4cda8b2381fa870276a00ca98ea Public tree identity: sha256:d02dd1e8d3547a489bb300741bed544bdc60bb8fe0bd541fd43ce9bfa7129a3e
This commit is contained in:
commit
8ded2b6a42
210 changed files with 76954 additions and 0 deletions
49
docs/security.md
Normal file
49
docs/security.md
Normal file
|
|
@ -0,0 +1,49 @@
|
|||
# Security
|
||||
|
||||
## Authority
|
||||
|
||||
Clusterflux separates four authority lanes:
|
||||
|
||||
- Client sessions for people.
|
||||
- Agent public-key signatures for non-interactive workflows.
|
||||
- Node public-key signatures for enrolled workers.
|
||||
- Operator credentials for hosted administrative actions.
|
||||
|
||||
The server derives tenant, project, identity, and permission scope from the
|
||||
authenticated lane. Request-body identity fields are not authority.
|
||||
|
||||
## Sessions and keys
|
||||
|
||||
Human login uses the configured identity provider and an opaque, nonce- and
|
||||
PKCE-bound transaction. The CLI never accepts provider claims or authorization
|
||||
codes as a session. Browser-login requests use a dedicated proxy route with
|
||||
per-client rate limiting. The hosted service binds only to loopback and does not
|
||||
use client-supplied forwarding headers as identity or authorization.
|
||||
|
||||
Enrollment grants are short-lived and single-use. Node and agent signatures bind
|
||||
the canonical request body, timestamp, nonce, key fingerprint, and scope.
|
||||
Forged, replayed, expired, revoked, cross-tenant, and body-modified requests
|
||||
fail.
|
||||
|
||||
Keep `.clusterflux/session.json`, node private keys, agent private keys, and
|
||||
operator credentials out of source control. Use protected environment files or
|
||||
your secret manager.
|
||||
|
||||
## Execution
|
||||
|
||||
The coordinator does not run arbitrary native user commands. Nodes execute
|
||||
commands within their reported capabilities. Linux container environments use
|
||||
rootless Podman and avoid privileged defaults.
|
||||
|
||||
Bundle size, canonical argument size, handle count, logs, task history, Debug
|
||||
Epoch state, relay state, and coordinator collections are bounded. Resource and
|
||||
relay reservations happen before unaffordable work or transfer begins.
|
||||
|
||||
## Artifacts
|
||||
|
||||
Artifact links are scoped, expiring, revocable, and bound to live metadata.
|
||||
Digest, size, producer, task attempt, and retaining source are checked. The
|
||||
coordinator retains metadata and bounded relay spool state, not durable artifact
|
||||
bytes by default.
|
||||
|
||||
Report security issues privately using [SECURITY.md](../SECURITY.md).
|
||||
Loading…
Add table
Add a link
Reference in a new issue