clusterflux-public/docs/security.md
Disasmer release dry run 2bef715211 Public dry run dryrun-20b59dc46b72
Source commit: 20b59dc46b72103c2f8a516c692b5cc3d54fab19

Public tree identity: sha256:aaa5ac7b58b2a0d23c6b11e5f76324bf3839ca1f62653a83deb736932adcfbd9
2026-07-14 10:08:15 +02:00

2.8 KiB

Security model

Disasmer runs untrusted project code as WebAssembly on attached nodes. Wasm is the isolation substrate; access to host operations is the capability boundary. Running a Wasm module alone does not grant commands, containers, source access, artifact access, networking, or coordinator authority.

Authority lanes

  • Client requests use an authenticated session scoped to one user, tenant, and project.
  • Nodes and non-interactive agents use Ed25519 request signatures, bounded timestamps, unique nonces, and explicitly scoped enrollment grants.
  • Identity requests create and poll browser-login transactions. The hosted callback exchanges the authorization code with Authentik and obtains identity from its authenticated user-info endpoint; the CLI cannot supply trusted identity claims.
  • Hosted Operator requests use a separate private credential and replay-safe proof. They are not Client protocol variants authorized by convention.

The coordinator uses its own clock for expiry, quota windows, and policy decisions. Quota meters are keyed by tenant, project, resource kind, and window. Client-provided actor or scope strings are not authority. Replay windows, login/enrollment transactions, task and debug histories, downloads, and artifact metadata all have explicit expiry or count bounds scoped to their authority or project/process object.

Transport and secrets

Remote control traffic must use HTTPS and follows normal certificate validation. Plain JSON-lines TCP and HTTP are restricted to loopback and require an explicit local-development mode on the coordinator. The hosted deployment terminates TLS at its reverse proxy and forwards only to a loopback service.

Node keys are generated from operating-system randomness. Local credential directories and files use Unix modes 0700 and 0600, reject symbolic-link paths, and are written atomically without overwriting an existing credential. Environment-provided keys remain the operator's storage responsibility.

Trust boundary

Rootless Podman is a useful additional containment and environment mechanism on Linux nodes, but it does not turn a denied host operation into an allowed one. Native commands require an explicit environment, cwd, bounded environment map, wall-clock timeout, output mount, and network policy. Linux container commands run with resource and process-count limits, no-new-privileges, and dropped capabilities; Wasmtime stores independently enforce memory/table/instance and fuel bounds. A limit failure is a bounded task failure and does not terminate the node daemon. Node operators decide which projects they trust and which host capabilities a node advertises. The community hosted service does not provide arbitrary hosted native execution; users attach their own nodes for real work.

Report vulnerabilities according to SECURITY.md.