Runtime boundary
Engine internals are removed from the global scope before Worker code runs. Resources enter the isolate through configured bindings.
Tenant boundary
Secrets, variables, bindings and storage are scoped to their service and tenant. Services sharing a node do not share each other's values or namespaces.
Credential boundary
Signed, time-limited credentials carry explicit scopes. Requests check their signature, expiry and current tenant state before granting access.
Checked egress
- Private, loopback, link-local and carrier-grade NAT ranges are blocked.
- Resolved addresses are checked to prevent DNS rebinding.
- Every redirect destination is checked again.
- Credential headers are removed when an origin changes.
Fleet identity
Peer connections use mutual TLS. Each node signs its lease records with a local Ed25519 key.
Verified callers
Workers receive authenticated caller information through ctx.access only after Peren verifies the signed identity header. Shared verification secrets do not enter Worker code.
Customer code
Dispatch namespaces and the Worker Loader run customer code with explicit bindings and deny-by-default access.
Container boundary
Container workloads receive host firewall rules through nftables or iptables so permitted internet access does not imply access to private networks or fleet peers.
Tested adversarially
Peren exercises isolation boundaries with adversarial cases covering engine internals, cross-service secrets, tenant storage prefixes and redirects aimed at private addresses.
Report a vulnerability
Report vulnerabilities privately through the channel listed in the repository profile or current release notes.
Do not open a public issue for a vulnerability, credential leak, isolation failure, privilege escalation, data corruption path or supply-chain concern.