Tighten tcib sudoers rules - #415
Conversation
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rabi The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Build failed (check pipeline). Post ✔️ tcib-openstack-meta-content-provider-master SUCCESS in 2h 08m 02s |
Drop the unneeded broad sudoers entries from the ansible-tests, horizontest, rally, and tobiko images, restrict Tempest to package installation, and replace the kolla wildcard rule with explicit helper commands. Keep the MariaDB bootstrap environment needed by kolla_security_reset so the tighter kolla allowlist does not break bootstrap. jira: OSPRH-34490 Signed-off-by: rabi <ramishra@redhat.com>
|
Build failed (check pipeline). Post ✔️ tcib-openstack-meta-content-provider-master SUCCESS in 2h 14m 51s |
|
recheck |
|
Build failed (check pipeline). Post ✔️ tcib-openstack-meta-content-provider-master SUCCESS in 3h 05m 14s |
|
recheck |
Drop the unneeded broad sudoers entries from the ansible-tests, horizontest, rally, and tobiko images, restrict Tempest to package installation, and replace the kolla wildcard rule with explicit helper commands.
Keep the MariaDB bootstrap environment needed by kolla_security_reset so the tighter kolla allowlist does not break bootstrap.
Depends-On: openstack-k8s-operators/mariadb-operator#537
jira: OSPRH-34490