fix(docker): require explicit env allowlist for container creds

This commit is contained in:
teknium1
2026-03-15 10:38:30 -07:00
parent 934fc9df22
commit b54591ddda
12 changed files with 171 additions and 3 deletions

View File

@@ -135,6 +135,8 @@ All container backends run with security hardening:
- Full namespace isolation
- Persistent workspace via volumes, not writable root layer
Docker can optionally receive an explicit env allowlist via `terminal.docker_forward_env`, but forwarded variables are visible to commands inside the container and should be treated as exposed to that session.
## Background Process Management
Start background processes and manage them: