Files
windmill/backend
Ruben Fiszel fd54cc694d fix(security): sandbox the PowerShell module install step under nsjail
The PowerShell module-install step ran `pwsh -Command <install_string>` directly
via start_child_process with no nsjail wrapping, unlike the run step which gates
on is_sandboxing_enabled(). Defense-in-depth: wrap the install step in nsjail
when sandboxing is enabled, using a dedicated install proto modeled on
run.powershell.config.proto but with the module cache mounted rw (so
Save-PSResource can still populate it) and the per-job script/result mounts
dropped.

Smoke-tested locally: nsjail starts, pwsh runs inside the jail (jailed /proc/1),
and writes to the rw cache mount succeed. NOT yet validated end-to-end is module
download from PSGallery / a private repo through the cloud tracing proxy — hence
draft.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 17:03:52 +00:00
..
2026-06-15 10:23:16 +02:00
2026-06-15 10:23:16 +02:00

Windmill Backend

This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.

Components

name description
windmill-api The API server, exposing functionality to other components and the frontend
windmill-audit Contains audit functionality, allowing different components to record important actions
windmill-common Common code shared by all crates
windmill-queue Contains job & flow queuing functionality, commonly written to by the API server and read from by workers
windmill-worker The worker. Used to process and execute flows & jobs.
parsers Contains code to parse signatures in different langauges.

Compile sqlx for offline ci

cargo sqlx prepare --workspace -- --bin windmill --features enterprise