Lightweight composition layer for Puppet TripleO
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
puppet-tripleo/releasenotes/notes/cold_migration_security-154...

10 lines
536 B

---
features:
- |
Restrict nova migration ssh tunnel
* The ssh authorized_keys file is only writeable by root.
* Creates a new user for migration instead of using root/nova.
* Disables SSH forwarding for this user.
* Restricts the networks that this user can connect from.
* Uses an ssh wrapper command to whitelist the commands that this user can run over ssh.
Adds new parameter "tripleo::profile::base::nova::migration_ssh_localaddrs" to specify which incoming IPs are allow for SSH tunnel connections.