September 10, 2019

 

Plantuml + Gitlab is risky

For a plantuml nice and simple diagrams text generation tool integration with the gitlab server setup, the plantuml server needs to be exposed to external network. Which is not good. Although some of security risks can be mitigated with running plantuml in docker but definitely not all (such as data exposure, DoS attacks) and mitigating them requires lots of careful manual tuning. Gitlab needs plantuml integration to host rendered images on its side. Maybe aa a plugin. I definitely want to investigate this.

Labels: , , , , , , , ,

Comments: Post a Comment



<< Home

This page is powered by Blogger. Isn't yours?