ArchitectureSecurity model
The data directory
The data directory holds all that Ferry knows, with the secrets. Only its owner can read it.
ferryd makes the data directory with mode 0700. Only the owner can open it.
1 / 4
--data-dir sets the data directory. The default is ./ferry-data. It holds all that Ferry knows, and that includes secrets:
- variable values and datastore passwords
- repository URLs with credentials
- the secrets of connected GitHub and GitLab accounts
- logs and uploaded source code
- TLS keys
Ferry does not encrypt secrets at rest
Variable values, datastore passwords and the secrets of connected git accounts are in plain text in ferry.db. Only the permissions of the directory protect them. Each person who can read the data directory, or its backups, can read each secret.
What to do
- Encrypt the backups.
- Restrict the access to the machine.
The files of the data directory lists each file and its mode.