mirror of
https://github.com/haproxy/haproxy.git
synced 2026-02-20 00:10:41 -05:00
DOC: config: mention uid dependency on the tune.quic.socket-owner option
This option defaults to "connection" but is also dependent on the user being allowed to bind the specified port. Since QUIC can easily run on non-privileged ports, usually this is not a problem, but if bound to port 443 it will usually fail. Let's mention this.
This commit is contained in:
parent
e64bccab20
commit
4d5f7d94b9
1 changed files with 3 additions and 1 deletions
|
|
@ -3422,7 +3422,9 @@ tune.quic.socket-owner { listener | connection }
|
|||
and cases of transient errors during sendto() operation are handled
|
||||
efficiently. However, this relies on some advanced features from the UDP
|
||||
network stack. If your platform is deemed not compatible, haproxy will
|
||||
automatically switch to "listener" mode on startup.
|
||||
automatically switch to "listener" mode on startup. Please note that QUIC
|
||||
listeners running on privileged ports may require to run as uid 0, or some
|
||||
OS-specific tuning to permit the target uid to bind such ports.
|
||||
|
||||
The "listener" value indicates that QUIC transfers will occur on the shared
|
||||
listener socket. This option can be a good compromise for small traffic as it
|
||||
|
|
|
|||
Loading…
Reference in a new issue