Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@membphis
Copy link
Member

the new permission 700 should be enough and more secure

Copy link
Contributor

@chibenwa chibenwa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This changeset imples that apisix and the java plugin runner are run by the same user: maybe this needs to be documented?

@membphis
Copy link
Member Author

This changeset imples that apisix and the java plugin runner are run by the same user: maybe this needs to be documented?

TIPS to user:
To improve security, it is strongly recommended to use a separate user for apisix-plugin-runner

@chibenwa
Copy link
Contributor

To improve security, it is strongly recommended to use a separate user for apisix-plugin-runner

Which is not possible with the proposed change.

Either we set 770 and use a common group between Apisix and the plugin runner
Or we could use a mechanism based on ACL permissions

Cf patch

socket-permission.patch.txt

@membphis
Copy link
Member Author

@chibenwa you can submit a new PR, your patch contains some java code, and I do not know if we need it

I will close this PR after you submit a new ^_^

@membphis
Copy link
Member Author

Need more PMCs to review your changing if there are correct

@chibenwa
Copy link
Contributor

Here we go @membphis

#318

@membphis membphis closed this Feb 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants