Note that once we avoid direct access to the state db from agents and clients, we will have the mongo port blocked off by the cloud firewall. Which does limit the effectiveness of this.
We also run jujud itself as root, but generally we have to because we do things like creating LXC containers and installing packages on the machine.
Note that once we avoid direct access to the state db from agents and clients, we will have the mongo port blocked off by the cloud firewall. Which does limit the effectiveness of this.
We also run jujud itself as root, but generally we have to because we do things like creating LXC containers and installing packages on the machine.