|
|
|
|
|
by matt4077
3222 days ago
|
|
I don't quite understand how this is different from the status quo? I guess gems may (sometimes) be installed with a different user (or even root) than the application server? But even if: most systems today probably only run that one service, and the application server can rwx pretty much everything of interest because that's its job, right? 10 years or so ago you'd often see some company's server running apache as well as a mail server, the internal document repository and the financial systems. In that sort of setup, it's important to (try to) keep these systems isolated from each other. But today, all that root access would give you is the ability to read a few more Ubuntu man pages. |
|