Security

CloudRING is meant to run clouds that many tenants share, so security has to be part of how it's built. This page lists what's in place today, with links to the code that does it, and what isn't.

No CloudRING release is approved for real deployments. Security fixes land on the main branch, but there’s no supported production distribution yet. To report a vulnerability, follow the disclosure policy.

Checks on every change

Sources: security.yml, supply-chain.yml, dependabot.yml and cla-dco.yml. Repository settings checked on 7 October 2026.

Release integrity

Sources: the release guide, release-provenance.yml and the published releases.

Both releases so far, v0.1.0-c01.1 and v0.1.0-c02.1, are development prereleases. You can check them yourself with the GitHub CLI. After downloading cloudring-linux-amd64.tar.gz from a release:

gh release verify v0.1.0-c02.1 --repo opencloudtech/CloudRING
gh attestation verify cloudring-linux-amd64.tar.gz \
  --repo opencloudtech/CloudRING \
  --signer-workflow opencloudtech/CloudRING/.github/workflows/release-provenance.yml

Security in the platform design

This is design and reference code, tested in the repository. It isn’t a guarantee about any live installation.

Network and runtime isolation between tenants is roadmap goal G05, which hasn’t started.

AI in development

Source: GOVERNANCE.md, “Review and acceptance authority”.

AI agents help write and review CloudRING’s code. Their changes go through the same pull requests and CI checks as anyone else’s, and the lead maintainer stays accountable for every change that’s accepted. AI tools also help review CloudRING’s code for security problems.

Planned before 1.0

Not in place

This website

This site is static HTML. It loads no third-party scripts, fonts, trackers or cookies, and it’s served with a strict Content Security Policy. Its security.txt follows RFC 9116.