Skip to content

Support Unix Domain Sockets #780

Description

@windsource

Description

Currently the server listens to an IP/port, by default 127.0.0.1:25551. If no mTLS is configured, every non-priviledged user on the same host can connect to that socket (e.g. via the ank CLI).
This insecure mode is intended for develoment and is the default for the installer and also for the packages. For development purposes a single node deployment might be sufficient and for that also Unix Domain Sockets (UDS) can be used as alternative to an IP connection. As UDS are file elements, those get permissions, users and groups. Thus normal Linux permissions schemes can be used to control access which is more simpler and provides better security than using IP without mTLS.

Goals

  • Enhance ank-server, ank-agent and ank to support UDS in addition
  • The installer and the packages shall use UDS by default
  • Restrict access to the Unix Domain Socket for Ankaios to root user and specific ankaios group, which is created by the installer and the packages. Thus every user who is member of the ankaios group can connect via UDS with ank to the ank-server.
  • For the installer and package use case, ank-agent and ank-server shall also communicate via UDS.

Final result

Summary

To be filled when the final solution is sketched.

Tasks

  • Task 1
  • Task 2
  • ...

Activity

  1. added
    enhancementNew feature or request. Issue will appear in the change log "Features"
    on Aug 20, 2026
  2. linked a pull request that will close this issueSupport unix domain sockets #784on Aug 27, 2026
  3. christoph-hamm commented on Aug 27, 2026

    @christoph-hamm
    Contributor

    I have create a PR to implement the UDS and to adapt the install script and the debian package. As the AUR package is in a different repository, we need an additional PR for it.

  4. added this to the v1.1 milestone on Sep 1, 2026
  5. christoph-hamm commented on Sep 28, 2026

    @christoph-hamm
    Contributor

    The PR is #784. I was wrong, the AUR package is part of the respository. I have updated it as well. From my point of view the this issues can be closed once the PR is merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

enhancementNew feature or request. Issue will appear in the change log "Features"

Type

No type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions