4 ms·
> almost as trivial for EC2 instances to expose XenStore as a filesystem to which standard UNIX permissions could be applied, providing IAM Role credentials wit
by rcaught 10y ago
> almost as trivial for EC2 instances to expose XenStore as a filesystem to which standard UNIX permissions could be applied, providing IAM Role credentials with the full range of access control functionality which UNIX affords to files stored on disk.
Doesn't this become more complicated when you think about EC2 offering Windows instances? Even with straight UNIX file writing, what writes this? Where does it write this? Which user has read permissions?
- skywhopper 10y agoYeah, having the metadata available over an http interface is actually brilliant. Simple HTTP calls are easy to do from any network-capable OS or language.
- jamiesonbecker 10y agoSo is reading a file on the filesystem.. easier, actually in most languages, since HTTP requests usually require loading an extra library.
- ChoHag 10y agoA library which uses the same (built-in) underlying IO mechanisms as the (built-in) filesystem.
- jamiesonbecker 10y agoIn UNIX, the same way that EBS volumes are mounted... think of the /proc or /sys virtual filesystems. In Windows, I'm guessing that this would be exposed as a network drive.
- rcaught 10y agoMy point is that these type of solutions create a lot more overhead, inconsistency and variation compared to a HTTP request; granted, less security.
- eeeeeeeeeeeee 10y agoI'm sure that's why they went with HTTP -- it is universal and will work the same way everywhere. I still think they should just disable it by default, so you have to "opt-in" to the potential security risk and plan accordingly.