Ability to Detect or Restrict Custom Docker Images in Runners
We’d love to see functionality in Spacelift that allows admins to detect or restrict the use of custom Docker images when running Terraform (or any command) via stacks. This would prevent the use of unverified images that could lead to secret leakage or execution of malicious logic.
- Problem
Log in to comment and vote
Comments1
Black Breeze
May 8, 2025
Write an approval policy, attach it to everything, look at run.runtime_config.runner_image and if it’s not on the allowlist, deny the run.