Security
Every request crosses a series of walls before it reaches a desktop. Here is each one, and the limits that are still open.
First wall
The fleet key.
The fleet refuses to start without a fleet key. Asking for a desktop, listing desktops or reading the pool all need it.
Second wall
A token per desktop.
Everything that names one desktop needs that desktop's own bearer token, shown once when the desktop is handed out.
Third wall
One way in.
The only path to a desktop's controls is through the fleet's proxy, which adds a per-desktop control token. The desktop checks it on every route except its health check.
Fourth wall
Its own network.
Each desktop sits on its own network, and in the shipped fleet no desktop port is published on the host. Egress can be switched off: the desktop then has no DNS and no route out.
Fifth wall
A container, for now.
Containers are the isolation boundary today, not a hypervisor. Good enough for demos, not for two unrelated tenants on one host.
Firecracker with its jailer is the locked choice for real multi-tenant isolation. Containers are for demos.
Then the desktop.
A request that clears every wall reaches one desktop: the one its token names.
Illustration. The dashed wall is the container. Scroll to pass through.
More walls
Some controls sit beside the request path rather than on it.
The fleet on a leash
The fleet talks to Docker through an allowlisting proxy: 12 dangerous requests got through before the allowlist, 0 after.
The screen viewer
Each desktop's screen viewer has its own password, delivered once.
Secrets shown once
A desktop's bearer token is 32 hex characters, and it is shown once.
Stopped means stopped
A stopped desktop keeps its home on its own disk and holds no container, network, ports or memory. Start brings it back.
Limits we have not closed
These are the shape of a prototype, not bugs waiting quietly for a fix.
A desktop can read its own control token.
A program running inside a desktop can read that desktop's own control token. Closing it means moving the control plane out of the desktop, which is the Firecracker work.
Containers, not a hypervisor.
Containers are the isolation boundary today, not a hypervisor. Good enough for demos, not for two unrelated tenants on one host.
Secrets on the host.
Tokens and the viewer password are visible to anyone with access to the machine.
Short viewer passwords.
Viewer passwords are 8 characters, the cap of classic VNC authentication.