Skip to main content

How Boat checks a request

Boat grants a request only when both of these are true:
  1. The action is in the action set of the key.
  2. The target sandbox is in the sandbox set of the key, or in one of its environments.
The default is deny. Boat refuses unknown routes for scoped keys.

Snapshots and environments

A destination environment does not give access to snapshots from other environments.

Actions

Presets

A key keeps the actions that it had when you created it. Resume, SSH and sandbox.delete-own joined the ci preset later. An older ci key does not get them. To get them, create a new ci key.

In-sandbox key

Boat writes a credential into each sandbox. This credential is scoped to that sandbox only. If an attacker takes control of a sandbox, they get access to that one sandbox only.

Errors

Scoped keys return typed 403 errors: The bearer header and the SDK configuration do not change.