-
Notifications
You must be signed in to change notification settings - Fork 23
yoga: Stop changing permissions on files in CIS #1179
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Contributor
markgoddard
commented
Jul 23, 2024
- Correct cve-2024-6387 reno
- Split Ubuntu Docker CE package into Focal/Jammy
- Disables password expiration and inactivity policies (Disables password expiration and inactivity policies #1106)
- Remove Kolla Ansible docker repo file on Jammy upgrade
- Make reboot timeout configurable in Ubuntu Jammy upgrade
- Only enable Apt CVE-2024-6387 repo on Jammy hosts
- ci-multinode: Add failing refstack tests to skip list
- Bump stackhpc.hashicorp role to 2.5.0
- Stop changing permissions on files on Rocky 9
- Stop changing permissions on files (Stop changing permissions on files #1119)
Split Ubuntu Docker CE package into Focal/Jammy
* Disables password expiration and inactivity policies This was causing the kayobe and kolla service accounts to be locked out of the system. * Remove flag that configures password expiry warning
When switching from Kolla Ansible repositories to release train, we need to remove the docker.list file that was added by Kolla Ansible.
The fix is not required on Focal, and the package is not compatible.
Ubuntu Jammy upgrade fixes
In Yoga and Zed there are 2 tests that fail due to using internal TLS but no external TLS. This breaks some URLs in API responses. This change adds them to skip lists. This should be reverted in Antelope, since it supports external TLS in multinodes.
This brings in a useful idempotency fix for Vault deployment. (cherry picked from commit bf535c6)
yoga: Bump stackhpc.hashicorp & multinode skip lists
These are causing changes to docker overlay filesystems with possible unintended consequences. It is also really slow to loop through so many files in ansible. (cherry picked from commit 0d1dfe2)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.