Is zriz safe? Security and your data
zriz is built so that database passwords and connection strings stay in your network. A value that you do not list in sensitive goes to the cloud.
- Does the cloud see my database password?
- What never leaves my network?
- What goes to zriz.io?
- Which connections does the runner make?
- What can the runner do?
- Can a zriz test change my data?
- Is my data kept apart from other orgs?
- What do the logs of zriz hold?
- Does zz hold a runner?
- Where is the code?
Does the cloud see my database password?
No, for a database connection. zriz is built so that zz or the runner holds the connection string, and the cloud has no database driver.
A different secret can go to the cloud in two cases:
- A value that you did not put in
sensitivegoes to the cloud. - A secret that you wrote in a pipeline file goes to the cloud with the file.
Put each secret in the file of the environment. List its name in sensitive.
What never leaves my network?
zriz is built so that the connection and the base-url of a resource stay in your network. Each value in sensitive stays too.
- The
connectionof an SQL resource. - The
base-urlof an HTTP resource. - Each value whose name is in
sensitive. - Each secret that a deployed runner reads from its own environment.
What goes to zriz.io?
The pipeline file and the resource files, without base-url and connection. Also each value that is not in sensitive, and the results that the checks need.
- The pipeline file.
- Each resource file, without
base-urlandconnection. - Each environment value whose name is not in
sensitive. - The fields of a reply that the checks need. For a check on
body.email, that field goes. - After a call fails: a part of the last reply, a maximum of 4096 bytes.
- The status and the times of the run.
zriz is built so that the runner removes each secret that it put into a call from each result. The cloud removes secrets again before it stores a run.
The key evidence of the runner config, with the value "none", stops the part of the last reply.
Which connections does the runner make?
Outbound connections only: to zriz.io, and to the resources in its config. zriz is built so that nothing listens. You open no port.
What can the runner do?
Only what the allowlist in its own config file permits. zriz is built so that a pipeline cannot make the runner call a different target.
- The runner calls only the resources that its config names.
- It compares each URL, and each redirect, with the origin of the resource: scheme, host, and port.
- On an SQL resource with
read-only, it refuses a statement that writes. It runs the query in a read-only transaction. - It fills a
${NAME}placeholder only in a permitted position, and never in an SQL query. - A
cliresource runs only the commands that the config permits.
The config file is in the runner guide.
Can a zriz test change my data?
Yes, when a step writes. An HTTP step can change data. An SQL step on a resource with read-only cannot.
| The step uses | Can it change data? |
|---|---|
| An HTTP resource | Yes. |
An SQL resource with read-only |
No. |
An SQL resource without read-only |
Yes. |
A cli or browser resource |
Yes. |
Run a test that writes against a test system. For a database, use an account that can only read, and also set read-only.
Is my data kept apart from other orgs?
Yes. zriz is built so that each record in the cloud belongs to one org. Each query reads the records of one org only.
What do the logs of zriz hold?
zriz is built so that its logs hold ids, kinds, reasons, and times. They hold no request body and no reply body.
Does zz hold a runner?
No. zriz is built so that zz and a runner are two programs. zz holds no runner and makes no call to your service.
Each run goes through a runner, and each runner obeys the same rules.
The secrets of a runner on this machine stay in .zriz/runner/runner.env on that machine. The cloud never gets them.
Where is the code?
The runner is open source. You can read the code that holds your secrets on a deployed runner. zz is not open source.