Friday, 2018-06-22

*** Bhujay has joined #openstack-sahara04:40
*** pgadiya has joined #openstack-sahara04:46
*** pgadiya has quit IRC04:46
*** masber has joined #openstack-sahara05:57
*** samueldmq has quit IRC06:28
*** samueldmq has joined #openstack-sahara06:28
*** pcaruana has joined #openstack-sahara06:30
*** rcernin has quit IRC07:08
*** whooligan_md has joined #openstack-sahara07:10
*** tesseract has joined #openstack-sahara07:11
*** whooliganface has quit IRC07:13
*** tosky has joined #openstack-sahara07:18
Bhujayjeremyfreudberg, tosky, tellesnobrega  , hdp image keeps some of the files in /tmp directory . For many organization , there will be need for OS hardening  , /tmp have several restriction including automatic deletion of files after each reboot and noexec . should we consider changing this path to soemwhere else..07:57
toskyBhujay: uhm, probably, yes; are those images generated with sahara-image-pack or sahara-image-elements?07:58
Bhujayimage-pack07:58
Bhujayas per cis standard /tmp  shd be mounted with noexec and mask to /var/tmp with autocleanup and after hardedning my images are not working , we can advise users to seek exemption but when time permits it may be good to change the location if possible08:01
toskythe point is: are those files still really needed, or just a by-product of the image generation?08:02
toskychecking the images that I have around, it seems that those files can be wiped anytime08:04
Bhujaylooks like .sh files are generated but there is download in UnlimitedPolicy08:04
*** rcernin has joined #openstack-sahara08:05
toskyI see, that's only for HDP in order to support kerberos integration08:05
toskyit's probably better to move it somewhere else, I concur08:06
Bhujaythe symptom is absense of some these file ( not sure which one ) tries to download the jar files in UnlimitedPolicy forcing me to have an internet connectivity from my cluster vm08:06
toskylocal_policy.jar, US_export_policy.jar; they are installed in the lib/security directory of the jdk08:07
toskyyes, they could be moved elsewhere, or we could even install them directly during the image building process08:08
Bhujayok08:09
Bhujayone more thing ...08:09
Bhujayis there any way the image build can be done behind a proxy ?08:10
toskycan you please open a story for those files? We need also to keep some code for compatibility08:10
Bhujaysure ,I will do that08:11
toskya proxy for image build with sahara-image-pack? I don't know out of my mind08:12
toskyit may be possible to simply make sure that the proxy variable set globally is passed to the internal steps which executes the validation08:14
toskybut it's something to investigate08:15
Bhujaysounds logical ,  and tried that through the image.yml env_var but could not succeed due to my limited knowledge ..08:15
Bhujaywhile running scripts there is a env_var passed  but for package there no such env_var , need to understand  how to do that08:16
toskybecause it's a "built-in" feature of the image building, so we probably need to consider something like http_proxy as special and always set it08:17
toskyor something like that08:17
toskyI guess we need another story, or we will forget :)08:17
Bhujaysure , I will do that too08:17
toskythanks08:18
*** Bhujay has quit IRC08:25
*** Bhujay has joined #openstack-sahara08:38
*** rcernin has quit IRC08:41
*** jeremyfreudberg has joined #openstack-sahara13:04
*** brad[] has quit IRC14:02
openstackgerritMerged openstack/sahara master: Use register_error_handler to register make_json_error  https://review.openstack.org/57661714:58
openstackgerritMerged openstack/sahara-tests master: Fix lintstack.py with Python3  https://review.openstack.org/57570714:58
*** afazekas has quit IRC15:00
*** afazekas has joined #openstack-sahara15:00
toskygates are unlocked \o/15:00
toskythanks again jeremyfreudberg15:00
openstackgerritJeremy Freudberg proposed openstack/sahara-extra master: Host some patched jars in common artifacts  https://review.openstack.org/57744915:20
*** Bhujay has quit IRC15:20
*** jeremyfreudberg has quit IRC15:50
*** tesseract has quit IRC16:02
*** pcaruana has quit IRC16:04
*** Bhujay has joined #openstack-sahara16:10
*** Bhujay has quit IRC16:14
*** Bhujay has joined #openstack-sahara16:14
*** Bhujay has quit IRC17:57
tellesnobregathanks jeremy for work on the gate18:57
openstackgerritHeba Naser proposed openstack/openstack-ansible-os_sahara master: Switch to using project-templates  https://review.openstack.org/57752319:30
*** tosky has quit IRC23:41

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!