logoalt Hacker News

azornathogrontoday at 2:44 PM1 replyview on HN

For one of my projects my server needs a private key, and it reads this from a file descriptor on startup and then closes the fd. The fd is set up by the systemd unit, which is also configured to restrict filesystem access for the server. So the server reads a key from a file that is never visible in its mount namespace.


Replies

computerfriendtoday at 3:02 PM

I do something similar with LoadCredential and it is quite amazing, especially when you want to run the application as a dynamic user.