Notes on ACL token storage and permissions

This commit is contained in:
Paul Banks 2018-03-02 16:22:12 +00:00
parent e833b535a6
commit c57451a414
No known key found for this signature in database
GPG Key ID: C25A851A849B8221
1 changed files with 4 additions and 4 deletions

View File

@ -139,10 +139,10 @@ will exit with an error at startup.
filesystem locking, meaning some types of mounted folders (e.g. VirtualBox
shared folders) may not be suitable. **Note:** both server and non-server
agents may store ACL tokens in the state in this directory so read access may
grant access to any tokens on servers and on any tokens used to register
services on non-servers. On Unix-based platforms the files are written with
0600 permissions so you should ensure only trusted processes can execute as
the same user as Consul. On Windows, you should ensure the directory has
grant access to any tokens on servers and to any tokens used during service
registration on non-servers. On Unix-based platforms the files are written
with 0600 permissions so you should ensure only trusted processes can execute
as the same user as Consul. On Windows, you should ensure the directory has
suitable permissions configured as these will be inherited.
* <a name="_datacenter"></a><a href="#_datacenter">`-datacenter`</a> - This flag controls the datacenter in