Skip to content

Encryption clarification #5419

Answered by vito
craigjbass asked this question in General
Apr 13, 2020 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Essentially, Concourse should not (yet) be used in situations where you anticipate having potentially malicious actors configure pipelines. While we run workloads in containers, this is primarily to protect your builds from themselves by providing a clean, isolated environment on each run, and not to protect your cluster from arbitrary user-submitted workloads that pipelines may run.

For example, if you were to run a central Concourse with open registration in order to run something like a hosted CI offering, you could quickly run into trouble as Concourse does not enforce safeguards that would prevent a user from submitting a build that is a "noisy neighbor" (i.e. starving your workers o…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@craigjbass
Comment options

Answer selected by vito
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants