Refuerzo de la cookie de distribución y el acceso a nodos
Restrinja qué nodos pueden conectarse a su clúster mediante cookies, listas de nodos permitidos y aislamiento de red para impedir accesos no autorizados.
Refuerzo de la cookie de distribución y el acceso a nodos es una lección gratuita de Erlang OTP: Distributed & Fault-Tolerant Systems Programming en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Erlang OTP: Distributed & Fault-Tolerant Systems Programming, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Erlang OTP: Distributed & Fault-Tolerant Systems Programming incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
How Nodes Authenticate
Erlang nodes form a cluster by sharing a secret cookie. Any node that knows the cookie and can reach the port may connect — and once connected, can run arbitrary code. This makes the cookie a critical secret.
The Magic Cookie
By default each node reads its cookie from ~/.erlang.cookie. If two nodes share it, they trust each other completely.
erlang:get_cookie().The Danger of Defaults
A weak or default cookie on a publicly reachable distribution port is a full remote-code-execution hole. Treat the cookie like a root password.
Setting a Strong Cookie
Set a long, random cookie explicitly at startup rather than relying on the file default.
erlang:set_cookie(node(), 'a-very-long-random-secret').Protecting the Cookie File
The cookie file must be readable only by its owner. Erlang refuses to start if permissions are too open.
chmod 400 ~/.erlang.cookieRestricting Node Names
Use net_kernel options and firewall rules so only known hostnames can even attempt a connection. Distribution should never be exposed to the open internet.
Binding the Distribution Port
Pin the distribution to specific ports and bind EPMD to a private interface so the cluster is unreachable from outside the trusted network.
erl -kernel inet_dist_listen_min 9100 inet_dist_listen_max 9105Monitoring Connections
nodes/0 lists currently connected nodes. Periodically auditing this list helps detect an unexpected peer.
nodes().Reacting to New Nodes
Subscribe to node up/down events with net_kernel:monitor_nodes/1 to log or reject connections you did not expect.
net_kernel:monitor_nodes(true).Hidden Nodes
Start tooling or monitoring nodes as hidden with -hidden so they connect without joining the full mesh, reducing the trust surface of your cluster.
erl -hidden -name tool@10.0.0.5 -setcookie SECRETDefense in Depth
Cookies alone are not enough. Combine them with TLS distribution, a private network (VPN/VLAN), firewalled EPMD, and least-privilege node placement.
Quick Check
Test your node security knowledge.
Recap
You learned to harden node access:
- The shared cookie is the cluster password — keep it long, random, secret
- Protect
~/.erlang.cookiewith 400 permissions - Bind distribution and EPMD to private interfaces; firewall them
- Audit connected nodes with
nodes/0and monitor events - Layer cookies with TLS and network isolation
Aprende Erlang con un tutor de IA — gratis
Escribe y ejecuta código real en tu navegador, obtén ayuda instantánea de un tutor de IA disponible 24/7 y continúa donde lo dejaste en la web o en la aplicación.
- Cursos
- 12
- Lecciones
- 48
Preguntas frecuentes
¿La lección «Refuerzo de la cookie de distribución y el acceso a nodos» es gratis?
Sí — el texto completo de «Refuerzo de la cookie de distribución y el acceso a nodos» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Erlang OTP: Distributed & Fault-Tolerant Systems Programming, actualiza a CoddyKit PRO. El curso de Erlang OTP: Distributed & Fault-Tolerant Systems Programming incluye 4 lecciones en total.
¿Qué aprenderé en «Refuerzo de la cookie de distribución y el acceso a nodos»?
Restrinja qué nodos pueden conectarse a su clúster mediante cookies, listas de nodos permitidos y aislamiento de red para impedir accesos no autorizados. Practicas Erlang OTP: Distributed & Fault-Tolerant Systems Programming con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar Erlang OTP: Distributed & Fault-Tolerant Systems Programming?
No se requiere experiencia previa. Erlang OTP: Distributed & Fault-Tolerant Systems Programming en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Refuerzo de la cookie de distribución y el acceso a nodos»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de Erlang OTP: Distributed & Fault-Tolerant Systems Programming?
Sí. Cada lección de Erlang OTP: Distributed & Fault-Tolerant Systems Programming incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- Comunicación segura entre nodos (TLS)
- Autenticación y autorización
- Protección de datos sensibles
- Refuerzo de la cookie de distribución y el acceso a nodos