mmmrrr
How to use an Elixir release without epmd
The title says it all:
I’d like to completely deactivate Erlang port mapper daemon for my application. Since it is running in a shared hosting setup, as far as I know, anyone could connect to it without any kind of authentication.
Also this particular application will never run in a clustered setup, so I think it is safe to say, that empd is not needed in this scenario.
Marked As Solved
tristan
Not sure with a mix release.
It is a feature I’ve been meaning to add to relx’s start script since someone brought up the same concern in the issues on it a little while ago.
The basic release run script isn’t too complicated, if it is of serious concern at the moment you can write your own – not sure how mix lets you include those in a release, but I’d assume it does somehow. Thats what I suggest to rebar3 users at the moment.
I guess so many of us are running in containers these days we see it as only being able to see the process if you can gain access to the containers pid namespace 
But if this isn’t possible with mix’s release script I’d suggest opening an issue. The script can be changed to rely on a .erlang.cookie file I think is the easiest way. But the key is to not read it in in the script if the user doesn’t want :). rebar3 has that issue, we support the file but we read it in to a variable and pass it to -setcookie. Not as simple a fix for us since we need that variable for other op actions at this time but Elixir shouldn’t since Jose put all that directly in iex.
Also Liked
Nicd
Mix release supports the environment variable RELEASE_DISTRIBUTION=none so using that when generating the release should disable distribution features. I don’t know if it avoids starting epmd but at least you shouldn’t be able to connect to the release.
I’m not a 100 % sure on these details so test before going into prod. Hoping someone wiser can chime in too.
Source: https://hexdocs.pm/mix/Mix.Tasks.Release.html#module-environment-variables
tristan
First, you can have epmd and the node itself bind to 127.0.0.1 so it is inaccessible outside of the host.
Next, there is https://github.com/tsloughter/epmdless which can be used to simplify running a node that you can get a remote connection to still locally but does not have epmd running.
Finally, OTP 23.1 will make this even simpler, removing the need for epmdless entirely in the case that you are fine with a static port being used for the Erlang node.
cmkarlsson
https://www.erlang-solutions.com/blog/erlang-and-elixir-distribution-without-epmd.html
The article is a bit old but perhaps still valid?
al2o3cr
Look into blocking the EPMD port at the interface (with iptables or equivalent new hotness); that way you can still SSH into the box and attach an IEx session like usual.
mmmrrr
This looks great. Thanks for sharing!
And also thanks to all the others for chiming in. I’m planning on trying all solutions suggested here and to report back when that happened. Thanks for all the contributions!







