3 ms·
Yeah -- I think I was just reciting what I hear folks say a lot. Basically its IPC and a stable interface for clients that is the core of the concern. Thats re
by kris-nova 4y ago
Yeah -- I think I was just reciting what I hear folks say a lot. Basically its IPC and a stable interface for clients that is the core of the concern. Thats really what the takeaway is.
- mariusor 4y agoBut Systemd has IPC and a stable interface for clients, it's "the D-Bus interface of systemd"[1]. I would think that exposing that over http would be a little reckless, but I'm sure one can create a proxy that can do it in a "secure"-ish way. [1] https://www.freedesktop.org/software/systemd/man/org.freedesktop.systemd1.html https://www.freedesktop.org/software/systemd/man/org.freedes...
- mike_hearn 4y agoThere is this: systemctl --host=whatever.abc status apache2 It uses ssh and UNIX domain socket forwarding behind the scenes. There's a writeup of how to do this with minimal privs here: https://sleeplessbeastie.eu/2021/03/03/how-to-manage-systemd-services-remotely/ https://sleeplessbeastie.eu/2021/03/03/how-to-manage-systemd... If you want to speak the protocol without the systemctl program then you can do the same trick. Use an SSH library, connect to the dbus socket and connect to systemd. You do need a dbus library though. They are less common than HTTP stacks.
- mariusor 4y agoTIL. I had no idea the systemd team implemented something like this already, it's great info, thank you. :)
- customkitchen 4y ago>They are less common than HTTP stacks. libsystemd includes a d-bus library for exactly this reason.