Drop root for ceilometer
Updates to ensure commands run in the ceilometer containers are done as the 'ceilometer' user rather than root. Change-Id: Ic94b876a002d4413f2038c29ffdb275c68323065 Partially-Implements: blueprint drop-root
This commit is contained in:
parent
d14666a51d
commit
d3efbd07dc
@ -11,3 +11,5 @@ RUN yum install -y openstack-ceilometer-alarm \
|
||||
{% endif %}
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
@ -14,3 +14,5 @@ COPY extend_start.sh /usr/local/bin/kolla_extend_start
|
||||
RUN chmod 755 /usr/local/bin/kolla_extend_start
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
@ -3,6 +3,6 @@
|
||||
# Bootstrap and exit if KOLLA_BOOTSTRAP variable is set. This catches all cases
|
||||
# of the KOLLA_BOOTSTRAP variable being set, including empty.
|
||||
if [[ "${!KOLLA_BOOTSTRAP[@]}" ]]; then
|
||||
sudo -H -u ceilometer ceilometer-manage db_sync
|
||||
ceilometer-manage db_sync
|
||||
exit 0
|
||||
fi
|
||||
|
@ -21,3 +21,5 @@ RUN ln -s ceilometer-base-source/* ceilometer \
|
||||
&& chown -R ceilometer: /etc/ceilometer /var/log/ceilometer /home/ceilometer
|
||||
|
||||
{% endif %}
|
||||
|
||||
RUN usermod -a -G kolla ceilometer
|
||||
|
@ -11,3 +11,5 @@ RUN yum install -y openstack-ceilometer-central \
|
||||
{% endif %}
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
@ -11,3 +11,5 @@ RUN yum install -y openstack-ceilometer-collector \
|
||||
{% endif %}
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
@ -14,3 +14,5 @@ RUN yum install -y \
|
||||
{% endif %}
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
@ -11,3 +11,5 @@ RUN yum install -y openstack-ceilometer-notification \
|
||||
{% endif %}
|
||||
|
||||
{{ include_footer }}
|
||||
|
||||
USER ceilometer
|
||||
|
Loading…
Reference in New Issue
Block a user