Docker-backed Web Bro applications
The restricted runtime profile used when a Web Bro app is launched through the School-GIT Docker host.
currentstatus
Runtime developers ยท Security developersaudience
School-GIT docssource
SCHX nativeruntime
SCHX / FEATURE LAYER
Source map
- lib/cdn/apps/docker-runtime.ts
- components/cdn/apps/DockerAppHost.tsx
- server.js
SCHX / FEATURE LAYER
Session lifecycle
The browser requests a runtime session. The server reconstructs immutable runtime files from URL-backed storage, validates the hashes, materializes only non-source runtime files and starts a short-lived container.
SCHX / FEATURE LAYER
Isolation profile
The Docker profile is an additional isolation layer, not a reason to skip publication scanning.
- Read-only app package mount.
- Dropped Linux capabilities.
- no-new-privileges enabled.
- CPU, memory and PID limits.
- Loopback/temporary host-port exposure through the generated runtime route.
- Restart disabled and short TTL for the Web Bro runtime session.
SCHX / FEATURE LAYER
Static web focus
The current docker-web profile is intended for built static web applications served from the container. Client-side JavaScript still executes in the browser.
SCHX / FEATURE LAYER