envoyproxy / envoyproxy/envoy

How to listen file descriptor, perhaps using systemd activation protocol

Open
#3,596 6 comments 1 reaction 0 assignees View on GitHub
design proposal help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 22h
Merged PRs (30d)
430

Description

It would be nice to be able to listen standard port 80 and 443 without starting envoy as root user. Systemd provides the standard protocol for that called [socket activation protocol](http://0pointer.de/blog/projects/socket-activation.html). There are also other ways to do the same with e.g. nginx even if it doesn't support that particular protocol.

Is there any equivalent of passing fd to envoy?

If you're not familiar with the concept. It's something like this: supervisor (for example systemd) binds a socket at port say 80. Then it puts the file descriptor into fixed number usually 3 (or starting from three if there are multiple) and removes CLOEXEC flag. So when process starts it has normal stdio file descriptors 0 (stdin), 1 (stdout), 2 (stderr), and also ``3`` which is a listening socket and can use the latter as a normal socket.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.