Protected Directories
When
the Data Collector
Security Manager is enabled, the following Data Collector
directories are protected directories:
$SDC_CONF
- Stages cannot access files in the configuration directory.$SDC_DATA
- Stages cannot access files in the data directory.$SDC_EXTERNAL_RESOURCES
- Stages can read files in the resources directory, but cannot write to files in the directory.$SDC_RESOURCES
- Stages can read files in the resources directory, but cannot write to files in the directory.
If needed, you can allow stages to access specific files in these protected directories
by modifying Data Collector
Security Manager exception properties in the $SDC_CONF/sdc-security.policy
fileSecurity Policy configuration properties
of the deployment. However, use caution when configuring exceptions to these protected directories.
You can configure exceptions to protected directories as follows:
- Exceptions for all stage libraries
- To allow all stage libraries access to files in protected directories,
modify the
security_manager.sdc_dirs.exceptions
property to define files that can be accessed. - Exceptions for specific stage libraries
- To allow a specific stage library access to files in protected directories,
add the following property and then define the files that the stage library
can
access:
security_manager.sdc_dirs.exceptions.<stage_library_name>=<file_path>
When you configure a Security Manager exception property, use the appropriate directory
environment variabledirectory environment
variable in the file path: $SDC_CONF
,
$SDC_DATA
, or $SDC_RESOURCES
. You can enter
multiple file paths separated by commas.