Skip to content

Lending: trust and privacy#

Lending a machine puts someone else's work on a machine you own. Each side keeps its own; this page says exactly where the line is.

The lender owns the machine#

The person who lends a machine has physical and administrator access to it. Whatever a borrower's work does there — files it writes, data it reads, what is in its memory, its network traffic — someone with root on that machine can see. Astralyx does not hide it from them, and cannot: no software on a machine is protected from its own administrator.

As a borrower: do not put sensitive data on a borrowed machine — secrets you cannot rotate, customers' or other people's personal data, anything under a confidentiality obligation. Use it for work whose inputs and outputs you would be comfortable sharing with its owner, and keep the results on a drive or a store of your own.

What the platform keeps apart#

The lender The borrower
Sees What the borrowed work used (GPU-, CPU-, memory-hours, network, disk, energy) per workspace and person; what ran: name, kind, image, workspace, person, machine, GPUs and their use, start, end. The lent machines, their hardware and metrics, the terms; the owner's work there only as taken (GPUs, cores, memory).
Never sees through Astralyx The borrowed work's logs, files, environment variables, commands or credentials; the borrower's other machines and work. The lender's other machines, their work, its names or owners; the lender's logs.
May do Change the terms, take the machines back at any time. Use the machines within the terms; give them back. Nothing of the machine itself (cordon, drain, labels, remove).

People of another organisation are named to a lender as a person of , unless they borrowed in person (then they accepted under their own name).

How borrowed work is held#

  • Sandboxed by default. Borrowed work runs under gVisor: its system calls are served by a kernel in user space, so a kernel bug it reaches is gVisor's, not the machine's. gVisor cannot reach GPUs here, so GPU work runs in a plain container — only where the lender allowed plain containers.
  • Never more than a container. No privileged mode, no host PID or IPC namespace, no added capabilities or security options, no bind mount of the machine's own paths — whatever the borrower's workspace was granted elsewhere.
  • Kept to the terms by the cluster. The cluster offers lent machines only within the terms, refuses to place work otherwise whoever asks, and stops borrowed work within seconds when the lending ends, its hours close, or (lent only when idle) the owner's work needs the GPUs.
  • The owner's power limit on the GPUs holds while borrowed work runs, and the machine's own comes back when it ends.

See also#