Keeping accounts apart on a server
On a shared server every hosting account runs its own PHP and, with SSH, its own shell. Without isolation a script of one customer can list the whole machine: every other customer's home directory, the names of every site, and every process
Written for: Administrator
On a shared server every hosting account runs its own PHP and, with SSH, its own shell. Without isolation a script of one customer can list the whole machine: every other customer's home directory, the names of every site, and every process that runs. With isolation on, an account sees its own home, its own processes, and nothing of the server's own configuration.
A new server gets isolation on (basic). A server that was set up before the feature existed keeps what it had until you turn it on.
Turning it on or off
On the server itself:
corectl isolation status # the mode, and what each account gets
corectl isolation set basic # on
corectl isolation set off # off againBoth are safe to repeat. corectl doctor says whether the isolation really reaches every account; the server advisor in the panel shows the same finding.
What is covered
- PHP. Every website's PHP runs inside the account's cage — on a server with PHP-FPM and on a LiteSpeed server alike.
- SSH, SFTP and cron jobs. Every login and every scheduled task of the account lands in the same cage.
The contents of other accounts' files were already protected by their permissions; what the cage takes away is the list: customer names, site names, mail domains and other people's processes.
PHP on a LiteSpeed server
LiteSpeed normally starts a website's PHP itself. With isolation on it no longer does: each account's PHP runs as a service of its own, which the server starts at the first visit and stops again after about five minutes without visitors. An account without visitors therefore costs no memory.
What you may notice:
- The first page after a quiet spell takes about a tenth of a second longer.
- If an account's PHP cannot start, its websites answer 503 and
corectl doctornames the account. PHP never falls back to running outside the cage.corectl reconcilestarts it again once the cause is fixed. - Webmail and phpMyAdmin are not part of any customer account and keep running the way they did.
With isolation off, LiteSpeed starts PHP itself again, as before.
Checking it for one account
corectl isolation status lists every account with what it gets. On a LiteSpeed server each PHP service of the account has a line of its own:
- caged, on demand (idle) — nobody has visited for a while; the next visit starts it.
- caged, running — it is serving visitors right now.
- FAILED or socket not listening — its websites answer 503. The line says which command shows why; after fixing the cause, run
corectl reconcile.
What is not hidden
The list of user names in /etc/passwd, the server's log directory and the names of listening sockets stay readable. A stricter mode that also hides those is planned but not built yet.