Security
Security architecture
The layers, and what each one is responsible for.
What this page will cover
- The fourteen layers, from edge to backup
- Privilege separation and the signed-job agent protocol
- Tenant isolation: users, pools, cgroups and filesystem boundaries
- Secret storage, rotation and the reveal-once model
- Audit event schema and retention
Why it is not here yet
The overview on the security page covers the model. This page is the detailed version.
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy