Erlang OTP: Distributed & Fault-Tolerant Systems Programming · Pelajaran

Memperkuat Cookie Distribusi & Akses Node

Batasi node yang dapat terhubung ke klaster Anda menggunakan cookie, daftar node yang diizinkan, dan isolasi jaringan untuk mencegah akses tanpa izin.

Pelajaran 4 dari 413 langkah

Memperkuat Cookie Distribusi & Akses Node adalah pelajaran Erlang OTP: Distributed & Fault-Tolerant Systems Programming gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Erlang OTP: Distributed & Fault-Tolerant Systems Programming, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Erlang OTP: Distributed & Fault-Tolerant Systems Programming mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

How Nodes Authenticate

Erlang nodes form a cluster by sharing a secret cookie. Any node that knows the cookie and can reach the port may connect — and once connected, can run arbitrary code. This makes the cookie a critical secret.

The Magic Cookie

By default each node reads its cookie from ~/.erlang.cookie. If two nodes share it, they trust each other completely.

erlang:get_cookie().

The Danger of Defaults

A weak or default cookie on a publicly reachable distribution port is a full remote-code-execution hole. Treat the cookie like a root password.

Setting a Strong Cookie

Set a long, random cookie explicitly at startup rather than relying on the file default.

erlang:set_cookie(node(), 'a-very-long-random-secret').

Protecting the Cookie File

The cookie file must be readable only by its owner. Erlang refuses to start if permissions are too open.

chmod 400 ~/.erlang.cookie

Restricting Node Names

Use net_kernel options and firewall rules so only known hostnames can even attempt a connection. Distribution should never be exposed to the open internet.

Binding the Distribution Port

Pin the distribution to specific ports and bind EPMD to a private interface so the cluster is unreachable from outside the trusted network.

erl -kernel inet_dist_listen_min 9100 inet_dist_listen_max 9105

Monitoring Connections

nodes/0 lists currently connected nodes. Periodically auditing this list helps detect an unexpected peer.

nodes().

Reacting to New Nodes

Subscribe to node up/down events with net_kernel:monitor_nodes/1 to log or reject connections you did not expect.

net_kernel:monitor_nodes(true).

Hidden Nodes

Start tooling or monitoring nodes as hidden with -hidden so they connect without joining the full mesh, reducing the trust surface of your cluster.

erl -hidden -name tool@10.0.0.5 -setcookie SECRET

Defense in Depth

Cookies alone are not enough. Combine them with TLS distribution, a private network (VPN/VLAN), firewalled EPMD, and least-privilege node placement.

Quick Check

Test your node security knowledge.

Recap

You learned to harden node access:

  • The shared cookie is the cluster password — keep it long, random, secret
  • Protect ~/.erlang.cookie with 400 permissions
  • Bind distribution and EPMD to private interfaces; firewall them
  • Audit connected nodes with nodes/0 and monitor events
  • Layer cookies with TLS and network isolation
Gratis untuk memulai

Belajar Erlang dengan tutor AI — gratis

Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.

Kursus
12
Pelajaran
48

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Memperkuat Cookie Distribusi & Akses Node” gratis?

Ya — teks lengkap “Memperkuat Cookie Distribusi & Akses Node” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Erlang OTP: Distributed & Fault-Tolerant Systems Programming, upgrade ke CoddyKit PRO. Kursus Erlang OTP: Distributed & Fault-Tolerant Systems Programming mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Memperkuat Cookie Distribusi & Akses Node”?

Batasi node yang dapat terhubung ke klaster Anda menggunakan cookie, daftar node yang diizinkan, dan isolasi jaringan untuk mencegah akses tanpa izin. Kamu berlatih Erlang OTP: Distributed & Fault-Tolerant Systems Programming dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Erlang OTP: Distributed & Fault-Tolerant Systems Programming?

Tidak diperlukan pengalaman sebelumnya. Erlang OTP: Distributed & Fault-Tolerant Systems Programming di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.

Berapa lama pelajaran “Memperkuat Cookie Distribusi & Akses Node” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Erlang OTP: Distributed & Fault-Tolerant Systems Programming ini?

Ya. Setiap pelajaran Erlang OTP: Distributed & Fault-Tolerant Systems Programming menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Komunikasi Node Aman (TLS)
  2. Autentikasi & Otorisasi
  3. Melindungi Data Sensitif
  4. Memperkuat Cookie Distribusi & Akses Node
← Kembali ke Erlang OTP: Distributed & Fault-Tolerant Systems Programming