Public dry run release-5ee549dd5fdd

Source commit: 5ee549dd5fddc98e4ee5054679bb0ac405c82529

Public tree identity: sha256:61b170dbdd26d350b8aff072e1792d38afd76bac7881bd42f271864d9662a6d4
This commit is contained in:
Clusterflux release dry run 2026-07-16 02:13:48 +02:00
commit e4e73e245a
210 changed files with 76592 additions and 0 deletions

48
docs/security.md Normal file
View file

@ -0,0 +1,48 @@
# Security
## Authority
Clusterflux separates four authority lanes:
- Client sessions for people.
- Agent public-key signatures for non-interactive workflows.
- Node public-key signatures for enrolled workers.
- Operator credentials for hosted administrative actions.
The server derives tenant, project, identity, and permission scope from the
authenticated lane. Request-body identity fields are not authority.
## Sessions and keys
Human login uses the configured identity provider and an opaque, nonce- and
PKCE-bound transaction. The CLI never accepts provider claims or authorization
codes as a session.
Enrollment grants are short-lived and single-use. Node and agent signatures bind
the canonical request body, timestamp, nonce, key fingerprint, and scope.
Forged, replayed, expired, revoked, cross-tenant, and body-modified requests
fail.
Keep ".clusterflux/session.json", node private keys, agent private keys, and
operator credentials out of source control. Use protected environment files or
your secret manager.
## Execution
The coordinator does not run arbitrary native user commands. Nodes execute
commands within their reported capabilities. Linux container environments use
rootless Podman and avoid privileged defaults.
Bundle size, canonical argument size, handle count, logs, task history, Debug
Epoch state, relay state, and coordinator collections are bounded. Resource and
relay reservations happen before unaffordable work or transfer begins.
## Artifacts
Artifact links are scoped, expiring, revocable, and bound to live metadata.
Digest, size, producer, task attempt, and retaining source are checked. The
coordinator retains metadata and bounded relay spool state, not durable artifact
bytes by default.
Report security issues privately to the repository owner rather than opening a
public issue with credentials, keys, or exploit details.