TIBCO Spotfire® Server and Environment Security

TERR Restricted Execution Mode (REX)

Scripts running in restricted execution mode (REX), but without container isolation, are running directly on the TERR service host using the same user account as is running the node manager on which the service runs.

The scripts are restricted in their capabilities (see terr.restricted.execution.mode). Enforcing all scripts to be running in both restricted execution mode and in container isolation provides an extra level of security and is recommended to achieve the highest level of security.