clusterflux-public/docs/security.md
Clusterflux release 6acd2d6eb7 Public release release-55b5a563d642
Source commit: 55b5a563d6421f49b5f5e77bc3c1f29752da8801

Public tree identity: sha256:52790e23e2b1806b00cc220c92edcfeed445600dcde620342af2b3369e7883fa
2026-07-16 17:13:43 +02:00

2 KiB

Security

Authority

Clusterflux separates four authority lanes:

  • Client sessions for people.
  • Agent public-key signatures for non-interactive workflows.
  • Node public-key signatures for enrolled workers.
  • Operator credentials for hosted administrative actions.

The server derives tenant, project, identity, and permission scope from the authenticated lane. Request-body identity fields are not authority.

Sessions and keys

Human login uses the configured identity provider and an opaque, nonce- and PKCE-bound transaction. The CLI never accepts provider claims or authorization codes as a session. Browser-login requests use a dedicated proxy route with per-client rate limiting. The hosted service binds only to loopback and does not use client-supplied forwarding headers as identity or authorization.

Enrollment grants are short-lived and single-use. Node and agent signatures bind the canonical request body, timestamp, nonce, key fingerprint, and scope. Forged, replayed, expired, revoked, cross-tenant, and body-modified requests fail.

Keep .clusterflux/session.json, node private keys, agent private keys, and operator credentials out of source control. Use protected environment files or your secret manager.

Execution

The coordinator does not run arbitrary native user commands. Nodes execute commands within their reported capabilities. Linux container environments use rootless Podman and avoid privileged defaults.

Bundle size, canonical argument size, handle count, logs, task history, Debug Epoch state, relay state, and coordinator collections are bounded. Resource and relay reservations happen before unaffordable work or transfer begins.

Artifacts

Artifact links are scoped, expiring, revocable, and bound to live metadata. Digest, size, producer, task attempt, and retaining source are checked. The coordinator retains metadata and bounded relay spool state, not durable artifact bytes by default.

Report security issues privately using SECURITY.md.