rultor
rultor copied to clipboard
Their is no information about the security model of rultor
@original-brownbear please dispatch this issue
@Egis-Moshe not sure what you have in mind here, could you elaborate ?
@original-brownbear How does rultor keep: a) it's github credentials secure b) encrypted secrets secure
@Egis-Moshe sorry for the slow reply:
Basically security is maintained this way:
- Ssh key and gpg key (for decrypting things) are stored on the Rultor host
- Builds are ran inside Docker containers
- The user can only freely specify the script to be ran inside the container
- The script for Git and decryption is ran on the host and fixed in the Rultor source code.
That what you'Re looking for ? :)
@original-brownbear something more along the lines of https://circleci.com/security/
Job gh:yegor256/rultor#1121 is in scope.
Job gh:yegor256/rultor#1121 assigned to @filfreire, please go ahead (policy).
@filfreire this job was assigned to you 5 days ago. It will be taken away from you soon, unless you close it, see par.8.
@filfreire this job was assigned to you 8 days ago. It will be taken away from you soon, unless you close it, see par.8.
@filfreire resigned from gh:yegor256/rultor#1121, please stop working.
Job gh:yegor256/rultor#1121 assigned to @filfreire, please go ahead (policy).
@filfreire resigned from gh:yegor256/rultor#1121, please stop working.
Job gh:yegor256/rultor#1121 assigned to @filfreire (profile). The budget is fixed and it is 30 minutes. Please, read the Policy and go ahead.
Oops! Job gh:yegor256/rultor#1121 already assigned to @filfreire, can't assign to @filfreire
@filfreire resigned from gh:yegor256/rultor#1121, please stop working.
@yegor256/z everybody who has role DEV are banned at this job; I won't be able to assign anyone automatically; consider assigning someone manually or invite more people to the project, as explained in §51
@0crat status
@0crat status (here)
@paulodamaso This is what I know about this job in C3SAYRPH9, as in §32:
- The job #1121 is in scope for 15mon
- The role is
DEV - The job is assigned to @paulodamaso/z for 6days
- There is no monetary reward attached, it's a free job
- The job doesn't have any impediments
- The budget is 30 minutes/points
- These users are banned and won't be assigned:
- Job footprint (restricted area)
@0crat refuse
@0crat refuse (here)
@paulodamaso The user @paulodamaso/z resigned from #1121, please stop working. Reason for job resignation: Order was cancelled
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)
@yegor256/z everybody who has role DEV is banned at #1121; I won't be able to assign anyone automatically; consider assigning someone manually (as in §19), or invite more people (as in §51), or remove the job from the scope (as in §14)