3 ms·
Yea, as of now there's no way around that. I'm working on adding 'sudo' logic into the script, but that doesn't seem any less risky security wise. Users are w
by melito 17y ago
Yea, as of now there's no way around that.
I'm working on adding 'sudo' logic into the script, but that doesn't seem any less risky security wise.
Users are welcome to use something like whowatch or a tty spy to view the progress of the script. What you see in the browser is what is going is happening on the machine.
Users are also welcome to set their passwords to something temporary and then change them when the deployer is complete.
In the end though, the only thing I can offer to put user's minds at ease is my word that I don't store any of their login info.
For the more technically curious I'm not even using a database right now. I just log the job id, the ip address you requested, and whether or not an email was successfully sent to the one you provided. Login information is only held in memory until the bootstrapper successfully connects to the machine. After that its gone.
As for the automated shell script, as of now it would be incredibly tedious to replicate something like this using standard shell scripting (for me at least). I've thought about adding a "copy to clipboard" button above the terminal, that would copy all the executed commands in the textarea. This could be pasted into a script, but it would still need some interaction from the user.
This is all very good feedback and I'm open to anymore that would help improve the project and make a better overall user experience.