The Graphoid instances running in production should be locked down as much as possible to avoid possible security issues caused by various penetration techniques. To that end, it should be firejail-ed.
Description
Description
Details
Details
Project | Branch | Lines +/- | Subject | |
---|---|---|---|---|
operations/puppet | production | +1 -1 | Enable firejail for graphoid |
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | MoritzMuehlenhoff | T101870 Service containment for nodejs-based services with firejail | |||
Resolved | MoritzMuehlenhoff | T103095 Confine Graphoid with firejail | |||
Resolved | Yurik | T103299 Graphoid tests fail |
Event Timeline
Comment Actions
@Yurik, could you provide a Graphoid URL that should return a valid PNG in deployment-prep so we can test?
Comment Actions
Change 219801 had a related patch set uploaded (by Muehlenhoff):
Enable firejail for graphoid