Security
gangway is root on its host
Section titled “gangway is root on its host”gangway talks to the Docker socket, which is root on that host. Give dashboard accounts and
tokens only to people you would trust with a shell there, or keep the dashboard and API on your
own network with GANGWAY_CONTROL_ALLOW (below). To keep that power off a machine that does other
work, run gangway in a VM; on Unraid,
gangway-inabox does it for you.
Previews are treated as hostile
Section titled “Previews are treated as hostile”- The Compose policy refuses host namespaces, bind mounts, devices, added capabilities, external networks and volumes, and other previews’ images.
- Every container runs with
no-new-privileges, withoutNET_RAW, and under memory and process limits. - Previews publish their ports on the host’s
127.0.0.1only, so gangway’s visibility gate is the only way in. - Secrets never reach a build context.
Previews can reach the internet and your LAN. If that matters, firewall the preview networks
(Docker’s DOCKER-USER chain), or give gangway a Docker host of its own.
Keep the dashboard private
Section titled “Keep the dashboard private”GANGWAY_CONTROL_ALLOW limits the dashboard and API, the root-on-this-host part, to the networks
you list, while previews, MCP and webhooks stay public. Everyone else gets the same “nothing here”
page as an unknown preview:
GANGWAY_CONTROL_ALLOW=192.168.1.0/24,100.64.0.0/10It judges the client address, so behind a proxy GANGWAY_TRUSTED_PROXIES must be right, and the
list must not include the proxy itself. Signing in to connect an agent, and “signed in” previews,
then work only from those networks.
Previews on their own domain
Section titled “Previews on their own domain”Previews share a site with the dashboard unless you set GANGWAY_PREVIEW_DOMAIN. The session
cookie is host-only and cross-site requests are checked by Origin, but a separate preview domain
is the stronger setup for untrusted pull requests.
Agents
Section titled “Agents”An agent gets only the scopes you approve on the consent page. artifacts lets it deploy only
static sites and artifacts, and touch only what it deployed itself. Secrets are write-only for
agents: they see names, never values. See Connect an agent.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Report it privately through GitHub’s Security → Report a vulnerability on the repository, or by email to security@gangway.sh, not in an issue. Only the latest release gets security fixes.