29 ms·
There are other benefits. UDS can be permissioned using standard unix USER/GROUP which adds more flexible security structure (more so when you combine UDS with
by _red 6y ago
There are other benefits.
UDS can be permissioned using standard unix USER/GROUP which adds more flexible security structure (more so when you combine UDS with SE Linux).
This is opposed to localhost which is much harder to firewall from-localhost->to-localhost
- lmilcin 6y agoI don't exactly see that as any better security. The assumption nowadays is that once something breached application safeties and has user level access to a machine it is as if it had root level access to that machine. The reason is that there is just too much surface between an application and the operating system to be able to guarantee safety. And so we put applications into their separate VMs or containers and treat the entire container as part of the application. There are no other assets on that container.
- toast0 6y agoIf the container boundary is meaningful, you can do things like run TLS termination in a container (because OpenSSL is a quagmire), and connect to the server via unix socket. Then the container has no need for outgoing network sockets, and limited filesystem access. Of course, if the container boundary isn't meaningful, you've complicated your system design for nothing. And either way, TLS termination in a separate process is a potentially significant penalty to performance, as you'll have a lot more copies.