fix: use nobody uid/gid as default values for webserver

Signed-off-by: Samuel Gaist <samuel.gaist@idiap.ch>
This commit is contained in:
Samuel Gaist
2026-02-11 20:46:59 +01:00
parent 1ec2d74546
commit 91d586900e
2 changed files with 4 additions and 4 deletions

View File

@@ -922,8 +922,8 @@ webserver:
# ```
ssl_certificate: /etc/falco/falco.pem
# User and group id under which the server should run
uid: 1000
gid: 1000
uid: 65534
gid: 65534
##############################################################################
# Falco logging / alerting / metrics related to software functioning (basic) #

View File

@@ -489,8 +489,8 @@ void falco_configuration::load_yaml(const std::string &config_name) {
}
m_webserver_config.m_prometheus_metrics_enabled =
m_config.get_scalar<bool>("webserver.prometheus_metrics_enabled", false);
m_webserver_config.m_uid = m_config.get_scalar<uint32_t>("webserver.uid", 1000);
m_webserver_config.m_gid = m_config.get_scalar<uint32_t>("webserver.gid", 1000);
m_webserver_config.m_uid = m_config.get_scalar<uint32_t>("webserver.uid", 65534);
m_webserver_config.m_gid = m_config.get_scalar<uint32_t>("webserver.gid", 65534);
std::list<std::string> syscall_event_drop_acts;
m_config.get_sequence(syscall_event_drop_acts, "syscall_event_drops.actions");