I am trying to make the case internally to use Bitbucket Pipelines as a CI alternative to our existing local build infrastructure and one of the concerns to be addressed is the security of the environment in which the builds happen.
There have been several security holes found in Docker that would allow data to leak from one container to another in an unintended way and it is highly likely that more exploits will be discovered as the technology evolves. To properly evaluate the risk it would be helpful to know the architecture that supports Pipelines and the containers it runs. For example; how many containers from different Bitbucket accounts are permitted to share a VM instance? How many on the same hypervisor? How many on the same hardware?
I haven't yet found answers to these questions in the documentation so information would be helpful; the more detail the better.
Thanks.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.