You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm missing the fact that I cannot limit what drivers the node will listen to. For instance I can disable exec in Consul, I wish I could only have docker in a set of nodes. Something like driver whitelist or blacklist would be great. This is mostly useful in conjunction with custom drivers or a specific exec binary to impose more organizationally imposed constraints on access to machines.
I work at a payment processor so I take a look mostly at security, isolation, and compliance concerns when using clustering tools and I hope this is useful to enrich nomad for even more production use cases. The way we look at Nomad we could use it as a low level component to enforce execution of highly audited works where compliance is very strict.
The text was updated successfully, but these errors were encountered:
I'm going to lock this issue because it has been closed for 120 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.
I'm missing the fact that I cannot limit what drivers the node will listen to. For instance I can disable exec in Consul, I wish I could only have docker in a set of nodes. Something like driver whitelist or blacklist would be great. This is mostly useful in conjunction with custom drivers or a specific exec binary to impose more organizationally imposed constraints on access to machines.
I work at a payment processor so I take a look mostly at security, isolation, and compliance concerns when using clustering tools and I hope this is useful to enrich nomad for even more production use cases. The way we look at Nomad we could use it as a low level component to enforce execution of highly audited works where compliance is very strict.
The text was updated successfully, but these errors were encountered: