Docs
Security
Contigra assumes nothing about the network or the workload.
Mutual TLS
Communication between the CLI, server, and runners is encrypted and mutually authenticated with mTLS. Enable it on the server with --enable-mtls.
Container sandboxing
Jobs run in containers on Docker or Podman, hardened by default:
- Non-root execution.
- Read-only filesystem.
- Dropped capabilities.
- Minimal privileges.
Authentication
Contigra supports JWT and API key authentication, with token management.
Audit logging
Security-relevant events are recorded in an audit log for review.
Reporting a vulnerability
Please report security issues privately rather than in public channels, by contacting the Nuvai team through nuvai.dev.