feat(serverless): add basic sandbox isolation and flexible driver options (#17176)
## Overview - Add a DISABLED serverless driver to explicitly turn off execution - Clarify self-hosting docs with driver options and recommended usage - Keep integration coverage for serverless function execution (default + external package example) ## Notes - Local driver remains the default for development usage; Lambda or Disabled recommended for production deployments - No functional changes to Lambda execution <!-- CURSOR_SUMMARY --> --- > [!NOTE] > Introduces flexible serverless execution modes and safer local execution. > > - **New driver:** `DISABLED` serverless driver with wiring in `serverless.interface`, factory, module provider, and GraphQL exception mapping; new exception code `SERVERLESS_FUNCTION_DISABLED`. > - **Local driver hardening:** Strip `NODE_OPTIONS` when spawning child processes; cleanup promise signature; better log capture. > - **Dependency build reliability:** Use `execFile` with bundled Yarn (`.yarn/releases/yarn-4.9.2.cjs`), strip `NODE_OPTIONS`, improved error messages, and parallel cleanup excluding `node_modules`. > - **Docs:** Add serverless section detailing `SERVERLESS_TYPE` options (LOCAL, LAMBDA, DISABLED), security notice, and recommended configs. > - **Config/env:** Default `IS_WORKSPACE_CREATION_LIMITED_TO_SERVER_ADMINS` set to `true` (examples/tests default `false`); sample envs updated. > - **Tests:** Add integration tests and GraphQL helpers for creating, updating, publishing, executing, and deleting serverless functions, including external package usage and error paths. > > <sup>Written by [Cursor Bugbot](https://cursor.com/dashboard?tab=bugbot) for commit 1a2958cc19cff1b0108c51b83095bbf95e75d931. This will update automatically on new commits. Configure [here](https://cursor.com/dashboard?tab=bugbot).</sup> <!-- /CURSOR_SUMMARY -->
This commit is contained in:
@@ -288,3 +288,44 @@ yarn command:prod cron:workflow:automated-cron-trigger
|
||||
<Warning>
|
||||
**Environment-only mode:** If you set `IS_CONFIG_VARIABLES_IN_DB_ENABLED=false`, add these variables to your `.env` file instead.
|
||||
</Warning>
|
||||
|
||||
## Serverless Functions
|
||||
|
||||
Twenty supports serverless functions for workflows and custom logic. The execution environment is configured via the `SERVERLESS_TYPE` environment variable.
|
||||
|
||||
<Warning>
|
||||
**Security Notice:** The local serverless driver (`SERVERLESS_TYPE=LOCAL`) runs code directly on the host in a Node.js process with no sandboxing. It should only be used for trusted code in development. For production deployments handling untrusted code, we highly recommend using `SERVERLESS_TYPE=LAMBDA` or `SERVERLESS_TYPE=DISABLED`.
|
||||
</Warning>
|
||||
|
||||
### Available Drivers
|
||||
|
||||
| Driver | Environment Variable | Use Case | Security Level |
|
||||
|--------|---------------------|----------|----------------|
|
||||
| Disabled | `SERVERLESS_TYPE=DISABLED` | Disable serverless functions entirely | N/A |
|
||||
| Local | `SERVERLESS_TYPE=LOCAL` | Development and trusted environments | Low (no sandboxing) |
|
||||
| Lambda | `SERVERLESS_TYPE=LAMBDA` | Production with untrusted code | High (hardware-level isolation) |
|
||||
|
||||
### Recommended Configuration
|
||||
|
||||
**For development:**
|
||||
```bash
|
||||
SERVERLESS_TYPE=LOCAL # default
|
||||
```
|
||||
|
||||
**For production (AWS):**
|
||||
```bash
|
||||
SERVERLESS_TYPE=LAMBDA
|
||||
SERVERLESS_LAMBDA_REGION=us-east-1
|
||||
SERVERLESS_LAMBDA_ROLE=arn:aws:iam::123456789:role/your-lambda-role
|
||||
SERVERLESS_LAMBDA_ACCESS_KEY_ID=your-access-key
|
||||
SERVERLESS_LAMBDA_SECRET_ACCESS_KEY=your-secret-key
|
||||
```
|
||||
|
||||
**To disable serverless functions:**
|
||||
```bash
|
||||
SERVERLESS_TYPE=DISABLED
|
||||
```
|
||||
|
||||
<Note>
|
||||
When using `SERVERLESS_TYPE=DISABLED`, any attempt to execute a serverless function will return an error. This is useful if you want to run Twenty without serverless function capabilities.
|
||||
</Note>
|
||||
|
||||
Reference in New Issue
Block a user