App isolation

Each app runs in its own sandbox, reaching only its own data.

Built on gVisor and Caddy

Plans: Every plan, including the free app

What you get

  • Each app in its own gVisor sandbox
  • A private network for each app
  • A database login that opens only the app's own data
  • Stored files under the app's own prefix
  • Cookies bound to each app's own address
  • A read-only file system and no root user

How it works

Every app runs inside gVisor, the open-source sandbox first built at Google, which stands between the app and the server's operating system. The app's files are read-only apart from a temporary folder, and it runs as an ordinary user, never as root.

Each app has a network of its own. Firewall rules let it reach its own database and the platform, and nothing that belongs to another app. Its database login opens only its own database, and its stored files sit under a prefix no other app can use.

Apps share a parent domain, so Caddy, the open-source web server in front of every app, binds every cookie to one app's exact address. One app cannot read or set another app's cookies, or the sign-in cookie. The security page has more detail, and web protection covers what happens before a request reaches the app.

Example

A plumbing merchant runs a public trade counter website and an internal margins app on the same account. If a flaw in the website's code were ever exploited, the sandbox and network rules would keep the attacker away from the margins data.

For your coding agent

database: app

Isolation needs no setting: app, the default, gives the app a database of its own. Write files only under /tmp and set cookies without a Domain attribute, as the rules for apps describe.

Read more

All features