transport/{TCP,TLS}: optional IP_FREEBIND / IP_BINDANY bind socketops
Allows to bind to an address even if it is not actually (yet or ever) configured. Fixes #238 Rationale: https://www.freedesktop.org/wiki/Software/systemd/NetworkTarget/#whatdoesthismeanformeadeveloper
This commit is contained in:
committed by
Christian Schwarz
parent
47ed599db7
commit
d35e2400b2
@@ -50,12 +50,18 @@ Serve
|
||||
serve:
|
||||
type: tcp
|
||||
listen: ":8888"
|
||||
listen_freebind: true # optional, default false
|
||||
clients: {
|
||||
"192.168.122.123" : "mysql01"
|
||||
"192.168.122.123" : "mx01"
|
||||
}
|
||||
...
|
||||
|
||||
.. _listen-freebind-explanation:
|
||||
|
||||
``listen_freebind`` controls whether the socket is allowed to bind to non-local or unconfigured IP addresses (Linux ``IP_FREEBIND`` , FreeBSD ``IP_BINDANY``).
|
||||
Enable this option if you want to ``listen`` on a specific IP address that might not yet be configured when the zrepl daemon starts.
|
||||
|
||||
Connect
|
||||
~~~~~~~
|
||||
|
||||
@@ -101,6 +107,7 @@ Serve
|
||||
serve:
|
||||
type: tls
|
||||
listen: ":8888"
|
||||
listen_freebind: true # optional, default false
|
||||
ca: /etc/zrepl/ca.crt
|
||||
cert: /etc/zrepl/prod.fullchain
|
||||
key: /etc/zrepl/prod.key
|
||||
@@ -110,6 +117,7 @@ Serve
|
||||
|
||||
The ``ca`` field specified the certificate authority used to validate client certificates.
|
||||
The ``client_cns`` list specifies a list of accepted client common names (which are also the client identities for this transport).
|
||||
The ``listen_freebind`` field is :ref:`explained here <listen-freebind-explanation>`.
|
||||
|
||||
Connect
|
||||
~~~~~~~
|
||||
|
||||
Reference in New Issue
Block a user