How applications are kept apart
Runtime isolation keeps each application apart from every other application, including the other applications in your own account. Each application runs in its own container, under its own credentials, and reaches its own secrets, database, and files, never another application's. This page lists what is kept apart and what your application must still check itself.
What each application has of its own
- Its container. Each application runs in its own container. The container's identity can pull only that application's image.
- Its platform credential. The platform keeps one platform credential for each environment of each application. A call made with it acts for that application alone.
- Its secrets. A secret stored for one application cannot be read by another. The platform's own secrets cannot be read by any application.
- Its database. Each environment has its own PostgreSQL database and role on the shared server. The role keeps that database apart from every other application's.
- Its files. A platform credential reaches its own application's storage areas. Every area belongs to one application. It cannot reach another application's areas, and no route reaches another account's files.
- Its external APIs. A declared upstream, an external API declared for one application, takes calls from that application only. Another application's platform credential cannot call it with the stored key.
Development and production
An application's environments are kept apart in the same way. Development and production each have their own platform credential, database, and storage partition. A call made in one environment does not reach the other's data.
Every application keeps development's records, even with one environment, production. Your local runs use them, so local test data never reaches the live database. End users are the one exception: on one environment the application has one list of end users, production's, and a local run's testers sign in there.
Outbound traffic
The egress firewall limits the hosts an application can reach. In enforce mode it blocks any host the manifest does not declare.
What your application still checks
Runtime isolation keeps applications apart. It does not keep the end users of one application apart from each other. The storage service does not separate files by end user, so your backend must check each end user's access before it reads or writes a file. Store files describes that check.
Related
- Egress firewall and request limits describes the outbound controls and the limits on incoming requests.
- Applications and environments explains an application's environments.
- Store a secret stores a secret for one application.
- Database describes each environment's database and role.