mirror of
http://git.haproxy.org/git/haproxy.git/
synced 2025-03-07 11:58:55 +00:00
DOC: config: mention uid dependency on the tune.quic.socket-owner option
This option defaults to "connection" but is also dependent on the user being allowed to bind the specified port. Since QUIC can easily run on non-privileged ports, usually this is not a problem, but if bound to port 443 it will usually fail. Let's mention this.
This commit is contained in:
parent
e64bccab20
commit
4d5f7d94b9
@ -3422,7 +3422,9 @@ tune.quic.socket-owner { listener | connection }
|
||||
and cases of transient errors during sendto() operation are handled
|
||||
efficiently. However, this relies on some advanced features from the UDP
|
||||
network stack. If your platform is deemed not compatible, haproxy will
|
||||
automatically switch to "listener" mode on startup.
|
||||
automatically switch to "listener" mode on startup. Please note that QUIC
|
||||
listeners running on privileged ports may require to run as uid 0, or some
|
||||
OS-specific tuning to permit the target uid to bind such ports.
|
||||
|
||||
The "listener" value indicates that QUIC transfers will occur on the shared
|
||||
listener socket. This option can be a good compromise for small traffic as it
|
||||
|
Loading…
Reference in New Issue
Block a user