Erlang OTP: Distributed & Fault-Tolerant Systems Programming · درس

تعزيز أمان Cookie التوزيع والوصول إلى العُقد

قيّد العُقد التي يمكنها الاتصال بالعنقود باستخدام ملفات cookies وقوائم العُقد المسموح بها وعزل الشبكة لمنع الوصول غير المصرح به.

الدرس 4 من 413 خطوة

تعزيز أمان Cookie التوزيع والوصول إلى العُقد درس مجاني في Erlang OTP: Distributed & Fault-Tolerant Systems Programming على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Erlang OTP: Distributed & Fault-Tolerant Systems Programming، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Erlang OTP: Distributed & Fault-Tolerant Systems Programming 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

How Nodes Authenticate

Erlang nodes form a cluster by sharing a secret cookie. Any node that knows the cookie and can reach the port may connect — and once connected, can run arbitrary code. This makes the cookie a critical secret.

The Magic Cookie

By default each node reads its cookie from ~/.erlang.cookie. If two nodes share it, they trust each other completely.

erlang:get_cookie().

The Danger of Defaults

A weak or default cookie on a publicly reachable distribution port is a full remote-code-execution hole. Treat the cookie like a root password.

Setting a Strong Cookie

Set a long, random cookie explicitly at startup rather than relying on the file default.

erlang:set_cookie(node(), 'a-very-long-random-secret').

Protecting the Cookie File

The cookie file must be readable only by its owner. Erlang refuses to start if permissions are too open.

chmod 400 ~/.erlang.cookie

Restricting Node Names

Use net_kernel options and firewall rules so only known hostnames can even attempt a connection. Distribution should never be exposed to the open internet.

Binding the Distribution Port

Pin the distribution to specific ports and bind EPMD to a private interface so the cluster is unreachable from outside the trusted network.

erl -kernel inet_dist_listen_min 9100 inet_dist_listen_max 9105

Monitoring Connections

nodes/0 lists currently connected nodes. Periodically auditing this list helps detect an unexpected peer.

nodes().

Reacting to New Nodes

Subscribe to node up/down events with net_kernel:monitor_nodes/1 to log or reject connections you did not expect.

net_kernel:monitor_nodes(true).

Hidden Nodes

Start tooling or monitoring nodes as hidden with -hidden so they connect without joining the full mesh, reducing the trust surface of your cluster.

erl -hidden -name tool@10.0.0.5 -setcookie SECRET

Defense in Depth

Cookies alone are not enough. Combine them with TLS distribution, a private network (VPN/VLAN), firewalled EPMD, and least-privilege node placement.

Quick Check

Test your node security knowledge.

Recap

You learned to harden node access:

  • The shared cookie is the cluster password — keep it long, random, secret
  • Protect ~/.erlang.cookie with 400 permissions
  • Bind distribution and EPMD to private interfaces; firewall them
  • Audit connected nodes with nodes/0 and monitor events
  • Layer cookies with TLS and network isolation
البدء مجانًا

تعلم Erlang مع معلم ذكاء اصطناعي — مجانًا

اكتب وقم بتشغيل أكوادك الفعلية في المتصفح، واحصل على مساعدة فورية من معلم ذكاء اصطناعي متاح 24/7، واستمر من حيث توقفت على الويب أو في التطبيق.

الدورات
12
الدروس
48

الأسئلة الشائعة

هل درس «تعزيز أمان Cookie التوزيع والوصول إلى العُقد» مجاني؟

نعم — نص درس «تعزيز أمان Cookie التوزيع والوصول إلى العُقد» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Erlang OTP: Distributed & Fault-Tolerant Systems Programming، انتقل إلى CoddyKit PRO. تتضمن دورة Erlang OTP: Distributed & Fault-Tolerant Systems Programming 4 دروس في المجموع.

ماذا ستتعلم في «تعزيز أمان Cookie التوزيع والوصول إلى العُقد»؟

قيّد العُقد التي يمكنها الاتصال بالعنقود باستخدام ملفات cookies وقوائم العُقد المسموح بها وعزل الشبكة لمنع الوصول غير المصرح به. تتمرن على Erlang OTP: Distributed & Fault-Tolerant Systems Programming مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Erlang OTP: Distributed & Fault-Tolerant Systems Programming؟

لا تُشترط خبرة سابقة. Erlang OTP: Distributed & Fault-Tolerant Systems Programming على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «تعزيز أمان Cookie التوزيع والوصول إلى العُقد»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Erlang OTP: Distributed & Fault-Tolerant Systems Programming هذا؟

نعم. كل درس في Erlang OTP: Distributed & Fault-Tolerant Systems Programming يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. اتصال العقد الآمن (TLS)
  2. المصادقة والتفويض
  3. حماية البيانات الحساسة
  4. تعزيز أمان Cookie التوزيع والوصول إلى العُقد
← العودة إلى Erlang OTP: Distributed & Fault-Tolerant Systems Programming