Slackbot
06/12/2023, 1:25 PMBruno Schaatsbergen
06/12/2023, 1:26 PMBruno Schaatsbergen
06/12/2023, 1:28 PMDylan Page
06/12/2023, 1:29 PMChris ter Beke
06/12/2023, 1:41 PMos.exec
commands but these run as the same user/context as the main process, meaning a client team can always create a branch, run some escalating shell commands to gain access to the private key, generate any JWT they want, and gain access to other client's GCP resources. Is there any way that a more isolated job model could fit into Atlantis' architecture (changing user IDs for jobs, changing chroot, running in containers, remote runners, etc.).Dylan Page
06/12/2023, 2:16 PMChris ter Beke
06/13/2023, 10:01 AMBruno Schaatsbergen
07/28/2023, 11:51 AMBruno Schaatsbergen
07/28/2023, 11:51 AMBruno Schaatsbergen
07/28/2023, 11:52 AMDylan Page
07/28/2023, 1:17 PM