FerryDocs
ArchitectureSecurity model

Known limitations

What the security model of Ferry does not have. Read this before you put a server on the internet.

Edit on GitHub
Other usersroles, audit logEncryptionof secrets at restIP allow listsBuild limitsdisk quotasPrivate imagesregistry login
What Ferry does not have

The list

  • One administrator account. No other users, teams, roles or audit log exist. Each API token has the same access. See What a token can do.
  • No encryption at rest. Ferry stores secrets in plain text in ferry.db. See The data directory.
  • No IP allow lists. The only rate limits are the connection limits and the limit on failed sign-ins, which is for the full server.
  • Gaps in the limits. Builds have no memory limit and no CPU limit. Disks have no quotas. Disk and network I/O have no limit. Each container can reach each service and datastore on the private network. See What Ferry does not contain.
  • No private registry. Docker must pull each image with no login. Ferry does not support the credentials of a private .

On this page