BITMOTECO Managers
Introduction
In the architecture emphasizing host and container separation, communication channels between containers and the host system are meticulously regulated to uphold security and isolation standards. Containers are exclusively permitted to communicate with specially integrated "managers" within the operating system, which serve as secure gateways for accessing system functions.
Isolation: Containers remain isolated from the host system, ensuring that any potential security breaches are contained within the container environment and do not compromise the integrity of the host.
Controlled Access: Direct communication between containers and the host system is restricted, with access to system functions mediated exclusively through integrated managers. This approach prevents unauthorized access and manipulation of critical system resources.
Security: By limiting communication pathways between containers and the host, the attack surface is minimized, reducing the likelihood of exploits and unauthorized access to sensitive system functionalities.
This documentation section elaborates on the mechanisms governing host communication with managers.
System Manager
The System Manager enables applications (e.g. encapsulated in containers) to perform defined system settings changes and actions on the host system. It serves as a privileged mediator between the host system and the application and provides an API in form of an JSON-RPC service where changes and action can be requested.
The most important features are:
- Shutdown/Reboot the System
- Get system information
- Set system configs
- Manage SSH
- Manage OS updates
Module Manager
The Module Manager manages the BITMOTECO modules on the BITMOTECOsystem. The main tasks are installation, uninstallation, updating, starting and stopping of modules. It offers both a command line interface as well as JSON-RPC API.
License Manager
The License Manager handles the license management tasks of the BITMOTECOsystem. It connects to a separate license Server (On Premises) and is able to check for available and valid product licenses. It offers an API interface so that the other BITMOTECO components (like the Module Manager) can connect with the License Manager, get information about the license states and activate or disable functions. If a module or a manager needs a license check, it only needs to be connected to the License Manager to benefit from its functions and does not need to implement the whole license check logic itself.