mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-21 16:02:28 +00:00
fd54cc694d
The PowerShell module-install step ran `pwsh -Command <install_string>` directly via start_child_process with no nsjail wrapping, unlike the run step which gates on is_sandboxing_enabled(). Defense-in-depth: wrap the install step in nsjail when sandboxing is enabled, using a dedicated install proto modeled on run.powershell.config.proto but with the module cache mounted rw (so Save-PSResource can still populate it) and the per-job script/result mounts dropped. Smoke-tested locally: nsjail starts, pwsh runs inside the jail (jailed /proc/1), and writes to the rw cache mount succeed. NOT yet validated end-to-end is module download from PSGallery / a private repo through the cloud tracing proxy — hence draft. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Windmill Backend
This folder holds all backend components, the src/ folder only contains files used to build the "root" binary.
Components
| name | description |
|---|---|
| windmill-api | The API server, exposing functionality to other components and the frontend |
| windmill-audit | Contains audit functionality, allowing different components to record important actions |
| windmill-common | Common code shared by all crates |
| windmill-queue | Contains job & flow queuing functionality, commonly written to by the API server and read from by workers |
| windmill-worker | The worker. Used to process and execute flows & jobs. |
| parsers | Contains code to parse signatures in different langauges. |
Compile sqlx for offline ci
cargo sqlx prepare --workspace -- --bin windmill --features enterprise