-
Notifications
You must be signed in to change notification settings - Fork 524
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
apm-server runs as root by default #1401
Comments
@prupert thanks! agreed, this is something we should do. |
Modifications needed:
We'll need to be test upgrades. |
The changes necessary to support this should be merged into libbeat shortly. After updating our vendored copy, this effort can proceed. By then #1421 should also be in to test any regressions introduced by this effort. One snag is that changing permissions from As a result, we will not change the default user in |
I am using the
apm-server-6.4.1-1.x86_64
package for CentOS 7 and noticed that theapm-server
process is running under theroot
user. This is probably not necessary and very insecure. A vulnerability inapm-server
can fully compromise the system.Suggested solution: run
apm-server
under it's own user with limited privileges.The text was updated successfully, but these errors were encountered: