Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-11496

Ensure builds are tied to dedicated agents for security

XMLWordPrintable

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Bamboo's current security model is insufficient for segregating development teams working on different security projects. Currently project A can be made to build on project B's build agent and a rogue developer in project A could use a modified build script to collect project B's source code from the agent's working copy.
      The option of deleting working copies after each build relies on manual (and therefore error prone) procedures and incurs significant performance overheads.
      I suggest providing an administrative function to dedicate build agents to specific projects which has the effect that the dedicated project is then only built on those dedicated agents, and no other project can be built on them.

            Unassigned Unassigned
            c1ef1437a4f6 S
            Votes:
            1 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: