tech-pkg archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
user/group names for webbish packages: fix/cleanup proposal
This email is a summary of what is and a suggestion for what we should
change. This is motivated by my quarterly pkgin ug on a bunch of
machines, which was mostly painless except for uid/gid confusion on web
packages, which lead to nextcloud not coming up.
* what is
We have a lot of webbish packages that interact, and often need
coordinated uid/gid and/or permissions. These are listed by variable
and default value, with a * if defined in mk/defaults/mk.conf (instead
of a package Makefile).
** apache
APACHE_USER www *
APACHE_GROUP www *
** nginx
NGINX_USER nginx
NGINX_GROUP nginx
(wip/freenginx is the same)
** anubis
APACHE_USER www
APACHE_GROUP www
** php_fpm
FPM_USER fpm
FPM_GROUP www
** php-nextcloud
APACHE_USER nginx
APACHE_GROUP nginx
This is an unusual situation, reusing APACHE_USER while redefining it.
Our nextcloud package does not depend on apache, nginx, or php_fpm, but
the standard approach is nginx/php_fpm.
* operational needs and commentary
For php web pages, I assert that the standard approach is php_fpm.
nginx connects to upstreams, e.g. anubis, php_fpm.
anubis listens on an IPv6 port, and does not appear to write files.
Thus it does not appear to have a need for a coordinated uid/gid.
php_fpm creates a socket e.g. /var/run/php84-fpm as root:www.
nginx must be operating under the same gid for this to work.
Overall, the current config blurs uid separation for daemons and
cross-package access control.
* suggested changes
- Do not have packages set APACHE_USER/GROUP to different values, on
the theory that these are user-settable values, and more importantly
that this is confusing.
- Decide if web servers should by default have access to programs that
expect to be accessed by web servers. Decide how this access should
work. I say yes; things should work without reconfig (while
otherwise following the Principle of Least Privilege). Access via
the filesystem should be by having web servers and server-called
programs in the same group.
The bikeshed question is if we should continue to have APACHE_USER/GROUP
be "www". The other choice is APACHE_USER/WWW_GROUP to make it clear
that the group is not about apache. I lean to WWW_GROUP.
Thus (avoiding APACHE_GROUP/WWW_GROUP as just paint color):
- Packages that *set* APACHE_USER/GROUP should stop setting those.
- Packages that aren't apache/modules that use APACHE_USER should stop
using that variable, and should define a variable for their package,
with a default for that package, e.g. ANUBIS_USER=anubis
- All web servers should use APACHE_GROUP as the group. This leads to
nginx being nginx:www.
- All programs that create sockets or files for web servers to connect
to or write to should use APACHE_GROUP
- Programs that don't create group-write sockets/files should either
have their own group.
Home |
Main Index |
Thread Index |
Old Index