Moved all docs from ./docs/ to ./web/documentation/ to be available on the website. No code changes. (0.40.5)
This commit is contained in:
parent
8f2847abfb
commit
567fa73796
224 changed files with 4584 additions and 1139 deletions
43
web/documentation/security-and-sandboxing.md
Normal file
43
web/documentation/security-and-sandboxing.md
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
---
|
||||
layout: page
|
||||
published: true
|
||||
noToc: true
|
||||
noComments: false
|
||||
noDate: false
|
||||
title: Fun - Security and Sandboxing
|
||||
subtitle: Trust boundaries, I/O expectations, and capability restrictions.
|
||||
description: Trust boundaries, I/O expectations, and capability restrictions.
|
||||
permalink: /documentation/security-and-sandboxing/
|
||||
lang: en
|
||||
tags:
|
||||
- documentation
|
||||
- handbook
|
||||
- installation
|
||||
- usage
|
||||
- introduction
|
||||
- help
|
||||
- guide
|
||||
- howto
|
||||
- docs
|
||||
- specifications
|
||||
- specs
|
||||
- repl
|
||||
---
|
||||
|
||||
# Security and Sandboxing
|
||||
|
||||
Understand the trust boundaries and how to run Fun code safely.
|
||||
|
||||
## Trust model
|
||||
- By default, Fun code can access functionality exposed by the stdlib and any enabled extensions.
|
||||
- File and network access depend on available modules and host configuration.
|
||||
|
||||
## Running untrusted code
|
||||
- Prefer running in a container/VM with restricted filesystem and network.
|
||||
- Limit available stdlib/modules by controlling `FUN_LIB_DIR` contents.
|
||||
- Use OS-level sandboxing (seccomp, AppArmor, SELinux, chroot) where applicable.
|
||||
|
||||
## Best practices
|
||||
- Avoid running as root.
|
||||
- Validate and sanitize inputs at module boundaries.
|
||||
- Keep your build minimal; disable unneeded extensions at compile time.
|
||||
Loading…
Add table
Add a link
Reference in a new issue