rultor icon indicating copy to clipboard operation
rultor copied to clipboard

Their is no information about the security model of rultor

Open moshloop opened this issue 9 years ago • 30 comments
trafficstars

moshloop avatar Jul 22 '16 07:07 moshloop

@original-brownbear please dispatch this issue

alex-palevsky avatar Jul 25 '16 14:07 alex-palevsky

@Egis-Moshe not sure what you have in mind here, could you elaborate ?

original-brownbear avatar Jul 28 '16 22:07 original-brownbear

@original-brownbear How does rultor keep: a) it's github credentials secure b) encrypted secrets secure

moshloop avatar Jul 28 '16 22:07 moshloop

@Egis-Moshe sorry for the slow reply:

Basically security is maintained this way:

  • Ssh key and gpg key (for decrypting things) are stored on the Rultor host
  • Builds are ran inside Docker containers
    • The user can only freely specify the script to be ran inside the container
    • The script for Git and decryption is ran on the host and fixed in the Rultor source code.

That what you'Re looking for ? :)

original-brownbear avatar Jul 31 '16 19:07 original-brownbear

@original-brownbear something more along the lines of https://circleci.com/security/

moshloop avatar Aug 01 '16 04:08 moshloop

Job gh:yegor256/rultor#1121 is in scope.

0crat avatar Nov 01 '17 09:11 0crat

Job gh:yegor256/rultor#1121 assigned to @filfreire, please go ahead (policy).

0crat avatar Nov 16 '17 20:11 0crat

@filfreire this job was assigned to you 5 days ago. It will be taken away from you soon, unless you close it, see par.8.

0crat avatar Nov 21 '17 20:11 0crat

@filfreire this job was assigned to you 8 days ago. It will be taken away from you soon, unless you close it, see par.8.

0crat avatar Nov 24 '17 20:11 0crat

@filfreire resigned from gh:yegor256/rultor#1121, please stop working.

0crat avatar Nov 26 '17 20:11 0crat

Job gh:yegor256/rultor#1121 assigned to @filfreire, please go ahead (policy).

0crat avatar Nov 26 '17 21:11 0crat

@filfreire resigned from gh:yegor256/rultor#1121, please stop working.

0crat avatar Dec 17 '17 17:12 0crat

Job gh:yegor256/rultor#1121 assigned to @filfreire (profile). The budget is fixed and it is 30 minutes. Please, read the Policy and go ahead.

0crat avatar Dec 28 '17 14:12 0crat

Oops! Job gh:yegor256/rultor#1121 already assigned to @filfreire, can't assign to @filfreire

0crat avatar Dec 28 '17 14:12 0crat

@filfreire resigned from gh:yegor256/rultor#1121, please stop working.

0crat avatar Jan 07 '18 14:01 0crat

@yegor256/z everybody who has role DEV are banned at this job; I won't be able to assign anyone automatically; consider assigning someone manually or invite more people to the project, as explained in §51

0crat avatar Apr 12 '18 11:04 0crat

@0crat status

paulodamaso avatar Jan 15 '19 16:01 paulodamaso

@0crat status (here)

@paulodamaso This is what I know about this job in C3SAYRPH9, as in §32:

  • The job #1121 is in scope for 15mon
  • The role is DEV
  • The job is assigned to @paulodamaso/z for 6days
  • There is no monetary reward attached, it's a free job
  • The job doesn't have any impediments
  • The budget is 30 minutes/points
  • These users are banned and won't be assigned:
    • @moshe-immerman/z: This user reported the ticket
    • @filfreire/z: User was resigned from the ticket
  • Job footprint (restricted area)

0crat avatar Jan 15 '19 16:01 0crat

@0crat refuse

paulodamaso avatar Jan 15 '19 16:01 paulodamaso

@0crat refuse (here)

@paulodamaso The user @paulodamaso/z resigned from #1121, please stop working. Reason for job resignation: Order was cancelled

0crat avatar Jan 15 '19 16:01 0crat

Tasks refusal is discouraged, see §6: -15 point(s) just awarded to @paulodamaso/z

0crat avatar Jan 15 '19 16:01 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Jan 15 '19 17:01 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Jan 20 '19 18:01 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Jan 25 '19 19:01 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Jan 30 '19 20:01 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Feb 04 '19 21:02 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Feb 09 '19 22:02 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Feb 14 '19 23:02 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Feb 20 '19 00:02 0crat

@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)

0crat avatar Feb 25 '19 01:02 0crat