Description
Currently the server listens to an IP/port, by default 127.0.0.1:25551. If no mTLS is configured, every non-priviledged user on the same host can connect to that socket (e.g. via the ank CLI).
This insecure mode is intended for develoment and is the default for the installer and also for the packages. For development purposes a single node deployment might be sufficient and for that also Unix Domain Sockets (UDS) can be used as alternative to an IP connection. As UDS are file elements, those get permissions, users and groups. Thus normal Linux permissions schemes can be used to control access which is more simpler and provides better security than using IP without mTLS.
Goals
- Enhance
ank-server, ank-agent and ank to support UDS in addition
- The installer and the packages shall use UDS by default
- Restrict access to the Unix Domain Socket for Ankaios to root user and specific ankaios group, which is created by the installer and the packages. Thus every user who is member of the ankaios group can connect via UDS with
ank to the ank-server.
- For the installer and package use case,
ank-agent and ank-server shall also communicate via UDS.
Final result
Summary
To be filled when the final solution is sketched.
Tasks
Description
Currently the server listens to an IP/port, by default 127.0.0.1:25551. If no mTLS is configured, every non-priviledged user on the same host can connect to that socket (e.g. via the ank CLI).
This insecure mode is intended for develoment and is the default for the installer and also for the packages. For development purposes a single node deployment might be sufficient and for that also Unix Domain Sockets (UDS) can be used as alternative to an IP connection. As UDS are file elements, those get permissions, users and groups. Thus normal Linux permissions schemes can be used to control access which is more simpler and provides better security than using IP without mTLS.
Goals
ank-server,ank-agentandankto support UDS in additionankto theank-server.ank-agentandank-servershall also communicate via UDS.Final result
Summary
To be filled when the final solution is sketched.
Tasks