Re: Kill in HN [message #3253 is a reply to message #3206] |
Thu, 18 May 2006 22:23 |
|
Seeing all the VPS processes (and files) and ability to do vzctl enter from the hardware node is a principle of OpenVZ. That makes VE mass management and troubleshooting possible. If something is wrong with the VPS, you can kill it from the host system.
At the same time, you are right, this is not good for security. Thus we do not recommend to run anything but the very basic stuff on the hardware node itself -- ideally, the only network port opened on hardware node is port 22, sshd. If you want to run anything else - create a VE and run it in this dedicated VE.
Kir Kolyshkin
|
|
|