Docs

Security

Contigra assumes nothing about the network or the workload.

Mutual TLS

Communication between the CLI, server, and runners is encrypted and mutually authenticated with mTLS. Enable it on the server with --enable-mtls.

Container sandboxing

Jobs run in containers on Docker or Podman, hardened by default:

  • Non-root execution.
  • Read-only filesystem.
  • Dropped capabilities.
  • Minimal privileges.

Authentication

Contigra supports JWT and API key authentication, with token management.

Audit logging

Security-relevant events are recorded in an audit log for review.

Reporting a vulnerability

Please report security issues privately rather than in public channels, by contacting the Nuvai team through nuvai.dev.