ArchitectureSecurity model
Known limitations
What the security model of Ferry does not have. Read this before you put a server on the internet.
The list
- One administrator account. No other users, teams, roles or audit log exist. Each API token has the same access. See What a token can do.
- No encryption at rest. Ferry stores secrets in plain text in
ferry.db. See The data directory. - No IP allow lists. The only rate limits are the connection limits and the limit on failed sign-ins, which is for the full server.
- Gaps in the limits. Builds have no memory limit and no CPU limit. Disks have no quotas. Disk and network I/O have no limit. Each container can reach each service and datastore on the private network. See What Ferry does not contain.
- No private registry. Docker must pull each image with no login. Ferry does not support the credentials of a private registry.