We discovered it was possible, when the agent was network booted, due to the model of "don't break existing users" coding, that it was possible for the script to consider a standing config drive as valid. This could result in configuration getting loaded from the configuration drive which is a security issue, but only for the networking portion of the configuration due to the use of glean instead of cloud-init. We since reverted out the default to have simple-init enabled, and this change fixes the load logic so we prevent these possible cases considering that ironic deployments using virtual media should now all be on code bases with the publisher ID value set. Change-Id: If2a63fd16d8ae8e71b61b39f7c0c87ff45a81cf0 Signed-off-by: Julia Kreger <juliaashleykreger@gmail.com>
ironic-python-agent-ramdisk
Builds a ramdisk with ironic-python-agent.
More information can be found at: https://docs.openstack.org/ironic-python-agent/latest/
Beyond installing the ironic-python-agent, this element does the following:
- Installs the
dhcp-all-interfacesso the node, upon booting, attempts to obtain an IP address on all available network interfaces. - Disables the
iptablesservice on SysV and systemd based systems. - Disables the
ufwservice on Upstart based systems. - Installs packages required for the operation of the ironic-python-agent::
-
qemu-utilspartedhdparmutil-linuxgenisoimage
- When installing from source,
python-devandgccare also installed in order to support source based installation of ironic-python-agent and its dependencies. - Install the certificate if any, which is set to the environment
variable
DIB_IPA_CERTfor validating the authenticity by ironic-python-agent. The certificate can be self-signed certificate or CA certificate. - Compresses initramfs with command specified in environment variable
DIB_IPA_COMPRESS_CMD, which is 'gzip' by default. This command should listen for raw data from stdin and write compressed data to stdout. Command can be with arguments. - Configures rescue mode if
DIB_IPA_ENABLE_RESCUEis not set tofalse. - By default, sets a maximum size for the ramdisk systemd journal to
15M. This can be disabled by setting
DIB_IPA_DISABLE_JOURNAL_MAX_LOG_SIZEto any value which is notFalse.
This element outputs three files:
$IMAGE-NAME.initramfs: The deploy ramdisk file containing the ironic-python-agent (IPA) service.$IMAGE-NAME.kernel: The kernel binary file.
Note
The package based install currently only enables the service when using the systemd init system. This can easily be changed if there is an agent package which includes upstart or sysv packaging.
Note
Using the ramdisk will require at least 1.5GB of ram