1
0
Fork 0
forked from fun/fun
fun/web/documentation/security-and-sandboxing/security-and-sandboxing.md

1.1 KiB

layout published noToc noComments noDate title subtitle description permalink lang tags
page true false false false Security and Sandboxing Trust boundaries, I/O expectations, and capability restrictions. Trust boundaries, I/O expectations, and capability restrictions. /documentation/security-and-sandboxing/ en
boundaries
capability
expectations
restrictions
sandboxing
security
trust

Understand the trust boundaries and how to run Fun code safely.

Trust model

  • By default, Fun code can access functionality exposed by the stdlib and any enabled extensions.
  • File and network access depend on available modules and host configuration.

Running untrusted code

  • Prefer running in a container/VM with restricted filesystem and network.
  • Limit available stdlib/modules by controlling FUN_LIB_DIR contents.
  • Use OS-level sandboxing (seccomp, AppArmor, SELinux, chroot) where applicable.

Best practices

  • Avoid running as root.
  • Validate and sanitize inputs at module boundaries.
  • Keep your build minimal; disable unneeded extensions at compile time.