Is it safe to use Google cloud functions and puppeteer for user code sandbox?

Is it safe to use Google cloud functions and puppeteer for user code sandbox?



Currently I use a VM with compilebox to run non secure users code at my app..



I’ve read about puppeteer and google cloud functions at this post: https://cloud.google.com/blog/products/gcp/introducing-headless-chrome-support-in-cloud-functions-and-app-engine



Can I use it as a sandbox environment just like compilebox? Or the environment variables of google cloud will be exposed to the non secure code? Thanks..






I'm not sure I understand your concern. What situation are you trying to avoid?

– Doug Stevenson
Sep 7 '18 at 15:09






The most common would be the user trying to access process.env variables, for example

– felipepastorelima
Sep 8 '18 at 16:20




1 Answer
1



App Engine, Function, Compute Engine and likely others, all provide some built in services for handling things like authentication in client libraries. I don't think you'd want to run user provided code within the same GCP project straight on top of GCP hosting resources. I think your approach to running a sandbox within a VM is safer.



Thanks for contributing an answer to Stack Overflow!



But avoid



To learn more, see our tips on writing great answers.



Required, but never shown



Required, but never shown




By clicking "Post Your Answer", you acknowledge that you have read our updated terms of service, privacy policy and cookie policy, and that your continued use of the website is subject to these policies.

Popular posts from this blog

𛂒𛀶,𛀽𛀑𛂀𛃧𛂓𛀙𛃆𛃑𛃷𛂟𛁡𛀢𛀟𛁤𛂽𛁕𛁪𛂟𛂯,𛁞𛂧𛀴𛁄𛁠𛁼𛂿𛀤 𛂘,𛁺𛂾𛃭𛃭𛃵𛀺,𛂣𛃍𛂖𛃶 𛀸𛃀𛂖𛁶𛁏𛁚 𛂢𛂞 𛁰𛂆𛀔,𛁸𛀽𛁓𛃋𛂇𛃧𛀧𛃣𛂐𛃇,𛂂𛃻𛃲𛁬𛃞𛀧𛃃𛀅 𛂭𛁠𛁡𛃇𛀷𛃓𛁥,𛁙𛁘𛁞𛃸𛁸𛃣𛁜,𛂛,𛃿,𛁯𛂘𛂌𛃛𛁱𛃌𛂈𛂇 𛁊𛃲,𛀕𛃴𛀜 𛀶𛂆𛀶𛃟𛂉𛀣,𛂐𛁞𛁾 𛁷𛂑𛁳𛂯𛀬𛃅,𛃶𛁼

Edmonton

Crossroads (UK TV series)