FerryDocs
ArchitectureSecurity model

The files of the data directory

Each file of the data directory, its mode and what it contains.

Edit on GitHub
<data-dir>
ferry-data/                 0700
├── api_token               0600
├── setup_code              0600
├── instance_id             0600
├── ferry.db
├── certs/
│   ├── <host>/key.pem      0600
│   └── accounts/*.json     0600
├── logs/
├── repos/
├── uploads/
└── builds/

A file with no in this picture has the protection of the 0700 directory.

What each file contains

FileContains
api_tokenThe server token
setup_codeThe setup code, only while the server has no account
instance_idThe claim of this data directory on its Docker name prefix
ferry.dbThe database of Ferry. See the next table.
certs/<host>/key.pem, certs/accounts/*.jsonTLS and the ACME account
logs/, repos/, uploads/, builds/Deploy and job logs, git mirrors, uploaded archives, build scratch space

What ferry.db contains

DataSecret part
Services, deploys, variables, env groups, settingsVariable values, in plain text
DatastoresTheir passwords, in plain text
Git connectionsTheir secrets: the private key of a GitHub App, tokens, the secret of an OAuth application
The accountThe hash of its password
Sessions and API tokensSHA-256 hashes only

Ferry does not encrypt this file. Read The data directory.

On this page