3 ms·
Thank you, I agree that this should be avoided as much as possible in general. Actually, in my company, we are pushing the logs to an external service, so I gu
by mpaepper 6y ago
Thank you, I agree that this should be avoided as much as possible in general.
Actually, in my company, we are pushing the logs to an external service, so I guess that line I wrote there was not totally thought out. ;)
However, it still might be useful for certain people to check servers for health or other metrics and you might not always have everything as perfect as you wish.
I guess you already stated that yourself.
So in general I'd agree. Good comment!
- gabereiser 6y agoHealth is a function of the application, not it’s host. A health check endpoint is paramount to ensuring the app is healthy. I still disagree with having _any_ access to a “box”. Local dev, console log, deployed debug? Better make sure you are logging events and not non-sense. Actionable events with request tracing (preferably). But yeah, it was a good article. Bitwarden is something I’ve used to share privileged keys before but the whole signing stuff was the right way to go. Also, if you aren’t on “cloud”, odds are you are still using something like Kubernetes or DC/OS or Swarm or the like. If you aren’t then well, wordpress sites aren’t really in the same ballpark technically. (Joke, Wordpress sites get traffic, some lots of traffic, I don’t discriminate against the PHP tribe).
- holoduke 6y agoI see your point. But you are incorrect and too much reasoning probably from your current position. In many new companies practicality is very important. There are maybe no resources to setup a giant set of utilities which replaces info you would normally get by SSH to a server. In a new company you wanna make this a graduate process. The security aspect is always important. But it's a balance. You cannot over engineer.