Erlang / Erlang Advanced Interview questions
Why do distributed Erlang nodes require a shared cookie?
The cookie is a shared secret string that every node in a cluster must present to authenticate itself before another node will accept a connection from it — without a matching cookie, a node can't join the cluster, send messages to remote PIDs, or make remote calls.
%% set via command line or ~/.erlang.cookie erl -sname nodea -setcookie mysecret
Without this check, any process capable of reaching a node's distribution port over the network could attach as a full cluster peer and execute arbitrary code, since distributed Erlang gives connected nodes deep capabilities (spawning processes, calling functions remotely). The cookie is a coarse, cluster-wide gate, not a fine-grained per-user authorization system, which is exactly why distributed Erlang is generally recommended only on trusted, isolated networks rather than exposed directly to the public internet.
More Related questions...