Distribution Cookie und Knotenzugriff absichern
Beschränken Sie mit Cookies, Listen zulässiger Knoten und Netzwerkisolation, welche Knoten sich mit Ihrem Cluster verbinden dürfen, und verhindern Sie unbefugten Zugriff.
Distribution Cookie und Knotenzugriff absichern ist eine kostenlose Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
How Nodes Authenticate
Erlang nodes form a cluster by sharing a secret cookie. Any node that knows the cookie and can reach the port may connect — and once connected, can run arbitrary code. This makes the cookie a critical secret.
The Magic Cookie
By default each node reads its cookie from ~/.erlang.cookie. If two nodes share it, they trust each other completely.
erlang:get_cookie().The Danger of Defaults
A weak or default cookie on a publicly reachable distribution port is a full remote-code-execution hole. Treat the cookie like a root password.
Setting a Strong Cookie
Set a long, random cookie explicitly at startup rather than relying on the file default.
erlang:set_cookie(node(), 'a-very-long-random-secret').Protecting the Cookie File
The cookie file must be readable only by its owner. Erlang refuses to start if permissions are too open.
chmod 400 ~/.erlang.cookieRestricting Node Names
Use net_kernel options and firewall rules so only known hostnames can even attempt a connection. Distribution should never be exposed to the open internet.
Binding the Distribution Port
Pin the distribution to specific ports and bind EPMD to a private interface so the cluster is unreachable from outside the trusted network.
erl -kernel inet_dist_listen_min 9100 inet_dist_listen_max 9105Monitoring Connections
nodes/0 lists currently connected nodes. Periodically auditing this list helps detect an unexpected peer.
nodes().Reacting to New Nodes
Subscribe to node up/down events with net_kernel:monitor_nodes/1 to log or reject connections you did not expect.
net_kernel:monitor_nodes(true).Hidden Nodes
Start tooling or monitoring nodes as hidden with -hidden so they connect without joining the full mesh, reducing the trust surface of your cluster.
erl -hidden -name tool@10.0.0.5 -setcookie SECRETDefense in Depth
Cookies alone are not enough. Combine them with TLS distribution, a private network (VPN/VLAN), firewalled EPMD, and least-privilege node placement.
Quick Check
Test your node security knowledge.
Recap
You learned to harden node access:
- The shared cookie is the cluster password — keep it long, random, secret
- Protect
~/.erlang.cookiewith 400 permissions - Bind distribution and EPMD to private interfaces; firewall them
- Audit connected nodes with
nodes/0and monitor events - Layer cookies with TLS and network isolation
Häufig gestellte Fragen
Ist die Lektion „Distribution Cookie und Knotenzugriff absichern“ kostenlos?
Ja — der vollständige Text von „Distribution Cookie und Knotenzugriff absichern“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Distribution Cookie und Knotenzugriff absichern“?
Beschränken Sie mit Cookies, Listen zulässiger Knoten und Netzwerkisolation, welche Knoten sich mit Ihrem Cluster verbinden dürfen, und verhindern Sie unbefugten Zugriff. Du übst Erlang OTP: Distributed & Fault-Tolerant Systems Programming mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Erlang OTP: Distributed & Fault-Tolerant Systems Programming zu starten?
Keine Vorkenntnisse erforderlich. Erlang OTP: Distributed & Fault-Tolerant Systems Programming auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Distribution Cookie und Knotenzugriff absichern“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion Code schreiben und ausführen?
Ja. Jede Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Sichere Knotenkommunikation (TLS)
- Authentifizierung und Autorisierung
- Schutz sensibler Daten
- Distribution Cookie und Knotenzugriff absichern