puppet-tripleo/spec/fixtures
Oliver Walsh f8ca94a5b7 Restrict nova migration ssh tunnel
This change enhances the security of the migration ssh tunnel:
- The ssh authorized_keys file is only writeable by root.
- Creates a new user for migration instead of using root/nova.
- Disables SSH forwarding for this user.
- Optionally restricts the networks that this user can connect from.
- Uses an ssh wrapper command to whitelist the commands that this user can run
  over ssh.

Requires the openstack-nova-migration package from
https://review.rdoproject.org/r/6327

bp tripleo-cold-migration

Change-Id: Idb56acd1e1ecb5a5fd4d942969be428cc9cbe293
2017-05-03 20:20:01 +00:00
..
hieradata Restrict nova migration ssh tunnel 2017-05-03 20:20:01 +00:00
hiera.yaml Add cinder profile spec tests 2016-12-05 08:26:55 -07:00