Skip to content

Enforce per-job ephemeral filesystem (no shared volumes) #9

@las7

Description

@las7

Problem

Shared workspaces and caches allow cross-job state leakage and disk exhaustion attacks.

Proposed change

Replace shared /tmp/tako-vm-jobs with:

  • per-job ephemeral volumes
  • persistent volumes only via explicit opt-in job types

Acceptance criteria

  • No shared writable filesystem between jobs.
  • Jobs are fully cleaned up after execution.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitysecurity related

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions