Re: enable/disable features in running configuration
Chris Adams <[email protected]>
| Newsgroups | gmane.linux.keepalived.devel |
|---|---|
| Message-ID | <[email protected]> |
Once upon a time, Alexandre Cassen <[email protected]> said: > this is my goal, I already partly introduced low-level design into lib. At least can provide CLI and users can make their security choice. I completely agree, exposing telnet listener to a routable IP address is horrible, but you can bind it locally, or we can provide a AF_UNIX choice too. will investigate other design as Jan proposed. Even bound-to-localhost is not a great idea, as it assumes nobody will ever run keepalived on a server with any untrusted users. Much better to just have a simple (non-CLI) protocol in the daemon that listens on a Unix socket. Then, if you want to provide a CLI, it can be a separate program that talks over the control socket. Also, I would recommend avoiding a Cisco-like CLI. The only good argument is that most like to copy Cisco, but it is really not a good CLI. If you want to copy somebody else's design, look at something like JUNOS. "commit confirm" for the win! -- Chris Adams <[email protected]> ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y