To reduce bot traffic you must login to view /lordwelch/gokrazy/src/commit/82d78edac8a87a3201b61df3c4a3ff1ed954fbe4/docs/quickstart/index.html.
The GitHub login only links via username.

Files

78 lines
2.8 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Process interface / requirements"
weight: 10
aliases:
- /userguide/process-interface/
---
## Process supervision
{{% notice tip %}}
You can find the corresponding code in
[func gokrazy.supervise](https://sourcegraph.com/search?q=context:global+repo:%5Egithub%5C.com/gokrazy/gokrazy%24+type:symbol+%5Esupervise%24&patternType=regexp&case=yes).
{{% /notice %}}
gokrazys init process (pid 1) supervises all the binaries the user specified via `gokr-packer` flags.
More specifically, gokrazy:
1. Starts your binary using Gos `os/exec.Command` API.
- The `stdout` and `stderr` file descriptors are hooked up to a ring buffer and can be viewed via gokrazys web interface.
- Extra command-line flags or environment variables can be specified using
[per-package configuration](/userguide/package-config/).
1. When your binarys process exits, gokrazy restarts it!
- If the process exits with status code `0` (or `125`), gokrazy will stop
supervision. Exiting immediately with status code `0` when the
`GOKRAZY_FIRST_START=1` environment variable is set means “dont start the
program on boot”
## Environment variables
gokrazy sets the `HOME` environment variable to `HOME=/perm/home/<cmd>`, where
`<cmd>` is the name of your binary. For example, `tailscale.com/cmd/tailscaled`
is started with `HOME=/perm/home/tailscaled`.
When your binary is first started, gokrazy sets the `GOKRAZY_FIRST_START=1`
environment variable.
The `PATH` environment variable is set to `/user:/gokrazy` so that all binaries
on the system can be discovered.
## Privilege dropping / security
An easy way to implement privilege dropping in Go is to re-execute the process
with [syscall.SysProcAttr](https://pkg.go.dev/syscall#SysProcAttr) fields
set. For example, this is how you would drop privileges to user `nobody`
(uid/gid 65534):
```go
// mustDropPrivileges re-executes the program in a child process,
// dropping root privileges to user nobody.
func mustDropPrivileges() {
if os.Getenv("NTP_PRIVILEGES_DROPPED") == "1" {
return
}
cmd := exec.Command(os.Args[0])
cmd.Env = append(os.Environ(), "NTP_PRIVILEGES_DROPPED=1")
cmd.Stdout = os.Stdout
cmd.Stderr = os.Stderr
cmd.SysProcAttr = &syscall.SysProcAttr{
Credential: &syscall.Credential{
Uid: 65534,
Gid: 65534,
},
}
log.Fatal(cmd.Run())
}
```
Examples:
- [`github.com/gokrazy/gokrazy/cmd/ntp`](https://sourcegraph.com/github.com/gokrazy/gokrazy/-/blob/cmd/ntp/privdrop.go)
is a rather involved example which retains the CAP_SYS_TIME capability in the
child process
- [`github.com/gokrazy/rsync`](https://sourcegraph.com/github.com/gokrazy/rsync/-/blob/internal/maincmd/namespacing_linux.go) uses Linux
mount namespaces and constructs a file system with read-only bind mounts of
the configured rsync modules