tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

user/group names for webbish packages: fix/cleanup proposal



This email is a summary of what is and a suggestion for what we should
change.  This is motivated by my quarterly pkgin ug on a bunch of
machines, which was mostly painless except for uid/gid confusion on web
packages, which lead to nextcloud not coming up.

* what is

We have a lot of webbish packages that interact, and often need
coordinated uid/gid and/or permissions.  These are listed by variable
and default value, with a * if defined in mk/defaults/mk.conf (instead
of a package Makefile).

** apache

APACHE_USER	www	*
APACHE_GROUP	www	*

** nginx

NGINX_USER	nginx
NGINX_GROUP	nginx

(wip/freenginx is the same)

** anubis

APACHE_USER	www
APACHE_GROUP	www

** php_fpm

FPM_USER	fpm
FPM_GROUP	www

** php-nextcloud

APACHE_USER	nginx
APACHE_GROUP	nginx

This is an unusual situation, reusing APACHE_USER while redefining it.
Our nextcloud package does not depend on apache, nginx, or php_fpm, but
the standard approach is nginx/php_fpm.

* operational needs and commentary

For php web pages, I assert that the standard approach is php_fpm.

nginx connects to upstreams, e.g. anubis, php_fpm.

anubis listens on an IPv6 port, and does not appear to write files.
Thus it does not appear to have a need for a coordinated uid/gid.

php_fpm creates a socket e.g. /var/run/php84-fpm as root:www.
nginx must be operating under the same gid for this to work.

Overall, the current config blurs uid separation for daemons and
cross-package access control.

* suggested changes

  - Do not have packages set APACHE_USER/GROUP to different values, on
    the theory that these are user-settable values, and more importantly
    that this is confusing.

  - Decide if web servers should by default have access to programs that
    expect to be accessed by web servers.  Decide how this access should
    work.  I say yes; things should work without reconfig (while
    otherwise following the Principle of Least Privilege).  Access via
    the filesystem should be by having web servers and server-called
    programs in the same group.

The bikeshed question is if we should continue to have APACHE_USER/GROUP
be "www".  The other choice is APACHE_USER/WWW_GROUP to make it clear
that the group is not about apache.  I lean to WWW_GROUP.

Thus (avoiding APACHE_GROUP/WWW_GROUP as just paint color):

  - Packages that *set* APACHE_USER/GROUP should stop setting those.

  - Packages that aren't apache/modules that use APACHE_USER should stop
    using that variable, and should define a variable for their package,
    with a default for that package, e.g. ANUBIS_USER=anubis

  - All web servers should use APACHE_GROUP as the group. This leads to
    nginx being nginx:www.

  - All programs that create sockets or files for web servers to connect
    to or write to should use APACHE_GROUP

  - Programs that don't create group-write sockets/files should either
    have their own group.


Home | Main Index | Thread Index | Old Index