How Boat checks a request
Boat grants a request only when both of these are true:- The action is in the action set of the key.
- The target sandbox is in the sandbox set of the key, or in one of its environments.
Snapshots and environments
A destination environment does not give access to snapshots from other environments.
Actions
Presets
A key keeps the actions that it had when you created it. Resume, SSH and
sandbox.delete-own joined the ci preset later. An older ci key does not get them. To get them, create a new ci key.
In-sandbox key
Boat writes a credential into each sandbox. This credential is scoped to that sandbox only.
If an attacker takes control of a sandbox, they get access to that one sandbox only.
Errors
Scoped keys return typed 403 errors:
The bearer header and the SDK configuration do not change.