OpenVZ Forum


Home » General » Support » VPS users interfere with HN ones
Re: VPS users interfere with HN ones [message #9501 is a reply to message #9498] Sun, 07 January 2007 21:05 Go to previous message
kir is currently offline  kir
Messages: 1645
Registered: August 2005
Location: Moscow, Russia
Senior Member

To add to what Rick just said:

(1) VE0, i.e. the host system itself, is considered to be «a parent» to all the VEs, thus it sees all the processes in all VEs. Sometimes this is handy for debugging VE-related problems. You can find out that VE a process with a given PID belongs to by checking the envID field in /proc/PID/status file.

(2) It is not recommended to run in VE0 anything but OpenVZ management-related tasks. I.e. it is not a good idea to have, say, MySQL installed in VE0 (just create a separate VE for it), or have ordinary users for the purposes other than OpenVZ HN administration tasks. The only networking daemon that you should run in VE0 should be sshd. If you will follow this recommendation you will not have problems with global process visibility. If you will not follow this recommendation, you could have severe security flaws/problems.


Kir Kolyshkin
http://static.openvz.org/userbars/openvz-developer.png
 
Read Message
Read Message
Read Message
Previous Topic: System RAM and OpenVZ Utilization
Next Topic: Supervisor VPS
Goto Forum:
  


Current Time: Wed Jul 23 01:09:23 GMT 2025

Total time taken to generate the page: 0.11155 seconds