From c57451a4140b534757494d77e9e53b31326d1ed1 Mon Sep 17 00:00:00 2001 From: Paul Banks Date: Fri, 2 Mar 2018 16:22:12 +0000 Subject: [PATCH] Notes on ACL token storage and permissions --- website/source/docs/agent/options.html.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/website/source/docs/agent/options.html.md b/website/source/docs/agent/options.html.md index 674591c857..970ba54afc 100644 --- a/website/source/docs/agent/options.html.md +++ b/website/source/docs/agent/options.html.md @@ -139,10 +139,10 @@ will exit with an error at startup. filesystem locking, meaning some types of mounted folders (e.g. VirtualBox shared folders) may not be suitable. **Note:** both server and non-server agents may store ACL tokens in the state in this directory so read access may - grant access to any tokens on servers and on any tokens used to register - services on non-servers. On Unix-based platforms the files are written with - 0600 permissions so you should ensure only trusted processes can execute as - the same user as Consul. On Windows, you should ensure the directory has + grant access to any tokens on servers and to any tokens used during service + registration on non-servers. On Unix-based platforms the files are written + with 0600 permissions so you should ensure only trusted processes can execute + as the same user as Consul. On Windows, you should ensure the directory has suitable permissions configured as these will be inherited. * `-datacenter` - This flag controls the datacenter in