OLD THREAT MODEL

OLD THREAT MODEL An architecture diagram generated by Archify. OLD THREAT MODEL · 3 attack surfaces: · Architecture component OLD THREAT MODEL 3 attack surfaces: 1. GitLab account · → repo access = deploy access · Architecture component 1. GitLab account → repo access = deploy access 2. Self-hosted runner · → local process runs untrusted CI scripts · Architecture component 2. Self-hosted runner → local process runs untrusted CI scripts 3. GitLab Pages · → artifact upload via CI token · Architecture component 3. GitLab Pages → artifact upload via CI token NEW THREAT MODEL · 1 attack surface: · Architecture component NEW THREAT MODEL 1 attack surface: 1. Wrangler auth token · → pages:write scope → stored in ~/.wrangler/ · Architecture component 1. Wrangler auth token → pages:write scope → stored in ~/.wrangler/ Legend Backend Database Security

Source summary

  • • 6 of 6 nodes shown
  • • 4 links preserved in the original
  • • OLD THREAT MODEL
  • • 1. GitLab account