Security Considerations for Runtime Types in Cloudflare Computer

Runtime types in Cloudflare Computer enforce security through capability-based isolation, runtime-ID validation, resource confinement, and strict RPC typing that prevents unauthorized access to host resources.

Cloudflare Computer isolates user code inside an on-demand runtime created for each execution request. The TypeScript types governing these runtimes—defined under packages/computer/src/runtime/—serve as the platform's primary security enforcement layer. This article examines how these runtime types address critical security concerns and prevent privilege escalation.

Capability-Based Isolation via WorkspaceRuntime

All filesystem and network operations flow through the WorkspaceRuntime object. This design ensures the runtime only exposes capabilities deliberately granted by the platform.

In packages/computer/src/runtime/runtime.ts, the runtime implementation filters out any attempt to access the host's process or globalThis objects. The runtime never leaks these privileged globals, making direct host compromise impossible.

// Runtime capabilities are gated through WorkspaceRuntime
import { Workspace } from "@cloudflare/computer";

async function runCommand(cmd: string) {
  const ws = new Workspace({ root: "/workspace" });
  // `ws.runtime.exec` validates the runtime ID internally
  const handle = await ws.runtime.exec(cmd);
  console.log(`Executed ${cmd} in runtime ${handle.runtimeId}`);
}

Runtime-ID Validation Prevents Resource Hijacking

Every execution handle carries a runtimeId. Before any operation—getExec, killExec, or disposeExec—the code asserts that the supplied ID matches the stored execution record.

The assertExecutionRuntime function in packages/computer/src/workspace.ts (lines 694-708) performs this validation. A malicious client attempting to hijack another execution's resources receives an assertion failure.

// Explicit runtime-ID verification
async function getExec(ws: Workspace, execId: string, expectedRuntimeId: string) {
  const exec = await ws.runtime.getExec({ id: execId, runtimeId: expectedRuntimeId });
  // Mismatched IDs throw an assertion error (workspace.ts:L694)
  return exec;
}

Resource Confinement Through ExecutionRuntimeTracker

The ExecutionRuntimeTracker type records CPU-time, memory, and I/O counters per runtime. Located in packages/computer/src/execution-runtime-tracker.ts, this tracker provides immutable accounting data to the scheduler for quota enforcement and runaway execution aborts.

The type definitions make resource consumption explicit and tamper-resistant for callers.

Disposable Stubs Eliminate Dangling Capabilities

Runtime-side RPC stubs are automatically disposed when executions finish. WorkspaceRuntime maintains a weak-reference map of active stubs and periodically flushes them via runtime.flushDeferredDisposers.

This mechanism in packages/computer/src/runtime/runtime.ts (lines 150-165) prevents capability resurrection attacks where terminated executions might leave exploitable handles.

// Safe runtime disposal clears all stubs
async function disposeRuntime(ws: Workspace, runtimeId: string) {
  await ws.runtime.disposeExec({ id: runtimeId });
  // Internal stub map is cleared, preventing reuse
}

No Privileged Host Access

The runtime executes inside Cloudflare Workers (or a FUSE shim) without direct OS privileges. Types like ExecLog in packages/computer/src/exec/types.ts deliberately limit exposed data to what workers can safely provide—excluding environment variables and secret keys.

Strict RPC Contract Typing

The capnproto-based RPC contract (docs/08_capnweb_interface.md) compiles to TypeScript interfaces in packages/rpc/src/interface.ts. Strong typing rejects malformed or malicious messages before they reach runtime logic, providing protocol-level security.

Key Security Files in Cloudflare Computer

File Security Function
packages/computer/src/runtime/runtime.ts Core WorkspaceRuntime implementation; capability checks and stub disposal
packages/computer/src/workspace.ts runtimeId validation via assertExecutionRuntime
packages/computer/src/execution-runtime-tracker.ts Immutable resource accounting for quota enforcement
packages/computer/src/exec/types.ts Minimal safe shapes for cross-runtime data
packages/rpc/src/interface.ts Strongly-typed RPC contract preventing malformed messages
docs/08_capnweb_interface.md Capnproto RPC specification

Summary

  • Capability-based isolation: WorkspaceRuntime gates all operations and hides host globals
  • Runtime-ID validation: Every operation verifies the execution belongs to the claimed runtime
  • Resource confinement: ExecutionRuntimeTracker enforces immutable quota accounting
  • Automatic disposal: Weak-reference stub maps prevent capability leakage post-execution
  • Strict typing: Capnproto-to-TypeScript compilation rejects malicious RPC payloads

Frequently Asked Questions

How does Cloudflare Computer prevent one execution from accessing another execution's resources?

Each execution receives a unique runtimeId that must be provided with every operation. The assertExecutionRuntime function in workspace.ts validates this ID against stored records, throwing an error on mismatch. This design prevents resource hijacking even if an attacker obtains another execution's handle.

What prevents user code from accessing the host operating system?

The runtime executes inside Cloudflare Workers or a FUSE shim without direct OS privileges. The WorkspaceRuntime implementation explicitly filters access to process and globalThis, and type definitions like ExecLog exclude sensitive data such as environment variables from cross-boundary messages.

How does Cloudflare Computer handle resource exhaustion attacks?

The ExecutionRuntimeTracker type maintains immutable counters for CPU time, memory, and I/O per runtime. The scheduler consults these counters to enforce quotas and forcibly terminate runaway executions before they impact other tenants or platform stability.

Why are RPC stubs disposed automatically rather than manually?

WorkspaceRuntime maintains active stubs in a weak-reference map with periodic flushing via flushDeferredDisposers. Automatic disposal eliminates human error in cleanup and prevents "dangling capability" attacks where forgotten stubs could be resurrected to access terminated execution contexts.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →