ArchitectureSecurity model
What Ferry does not contain
Builds, disks, I/O and the private network have no limit. Know these gaps before you deploy code.
A build has no memory limit and no CPU limit. It can use all the memory and CPU of the host.
1 / 4
The gaps
| Not contained | Detail |
|---|---|
| Builds | docker build runs in BuildKit, which has no memory limit and no CPU limit per build. Only --build-concurrency (default 2) limits builds. The free-disk check runs before a build, not during it. |
| Disks | Volumes (datastores, service disks), the filesystems of containers, images and the build cache have no quotas. A service that writes to its disk or to its filesystem can fill the disk of the host. |
| Disk and network I/O | No I/O limit and no bandwidth limit exist. |
| The private network | All services and datastores share one private network. Each container can reach each service and datastore by name. Only their passwords protect the datastores. |
A limit of 0 turns a guard off
--default-memory-limit 0, --default-cpu-limit 0, --pids-limit 0, --log-max-size 0 and --min-free-disk 0 each turn one guard off.
Keep the disk free
The free-disk check stops only new deploys and new datastores. --keep-images limits the images of Ferry. You must prune the rest:
docker image prune
docker builder pruneSee Production setup and the networking model.