C++ SCHX ยท rev 4
Runtime isolation ยท current

Docker-backed Web Bro applications

The restricted runtime profile used when a Web Bro app is launched through the School-GIT Docker host.

currentstatus
Runtime developers ยท Security developersaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER

Source map

  • lib/cdn/apps/docker-runtime.ts
  • components/cdn/apps/DockerAppHost.tsx
  • server.js
SCHX / FEATURE LAYER

Session lifecycle

The browser requests a runtime session. The server reconstructs immutable runtime files from URL-backed storage, validates the hashes, materializes only non-source runtime files and starts a short-lived container.

SCHX / FEATURE LAYER

Isolation profile

The Docker profile is an additional isolation layer, not a reason to skip publication scanning.

  • Read-only app package mount.
  • Dropped Linux capabilities.
  • no-new-privileges enabled.
  • CPU, memory and PID limits.
  • Loopback/temporary host-port exposure through the generated runtime route.
  • Restart disabled and short TTL for the Web Bro runtime session.
SCHX / FEATURE LAYER

Static web focus

The current docker-web profile is intended for built static web applications served from the container. Client-side JavaScript still executes in the browser.

SCHX / FEATURE LAYER

Related documentation