What would you like to be added?
Currently the API endpoint only supports listening on a normal TCP port. I would like to see support for creating and listening on a Unix socket.
Why is this needed?
TCP Ports have several drawbacks. Collisions are the most common one and can confuse new users when setting up crowdsec. Especially as it uses port 8080 by default which is quote a common port already for any kind of HTTP server. Another drawback is limited access control for local processes. Any process running on the local machine (or some process gone rouge) can access the server.
UDS do not have these problems. They do not suffer from the same port collision issue and access can easily be controlled through the usual file and directory access permissions.
Especially the fact that this completely avoids port collision issues is very advantageous for those having their first go at crowdsec
What would you like to be added?
Currently the API endpoint only supports listening on a normal TCP port. I would like to see support for creating and listening on a Unix socket.
Why is this needed?
TCP Ports have several drawbacks. Collisions are the most common one and can confuse new users when setting up crowdsec. Especially as it uses port 8080 by default which is quote a common port already for any kind of HTTP server. Another drawback is limited access control for local processes. Any process running on the local machine (or some process gone rouge) can access the server.
UDS do not have these problems. They do not suffer from the same port collision issue and access can easily be controlled through the usual file and directory access permissions.
Especially the fact that this completely avoids port collision issues is very advantageous for those having their first go at crowdsec