zun/zun/cmd
Hongbin Lu d9098aab26 Introduce rootwrap and filter
If the zun-compute process is owned by a user who doesn't have
passwordless sudo privilege, zun-compute will fail to run
privileged command (e.g. sudo privsep-helper ...).

A native solution is to grant passwordless sudo to the user
who owns the zun process, but the best practice is to leverage
Rootwrap [1], which can restrict the privilege escalation.

This patch make Zun leverage Rootwrap. In particular, it does
the following:
* Setup Rootwrap in the Zun devstack plugin
* Introduce a sample rootwrap config file
* Introduce sample rootwrap filters for executing privsep-helper
* Introduce a root helper which basically adds "sudo zun-rootwrap"
  to the beginning of the command to be execute.
* Initialize privsep to use the Zun's root helper

[1] https://wiki.openstack.org/wiki/Rootwrap

Closes-Bug: #1749342
Needed-By: I69c47d25fa53f8e08efad9daa71d2f550425a5e7
Change-Id: I3ca5d853588b3705cb6cb2410df16e16a621c030
(cherry picked from commit d412de7100)
2018-03-20 13:58:01 +00:00
..
__init__.py Integrate OSProfiler in Zun 2017-03-17 21:15:03 +08:00
api.py Fix an issue in zun-api start 2017-03-27 22:07:07 +05:30
compute.py Introduce rootwrap and filter 2018-03-20 13:58:01 +00:00
db_manage.py update higgins with zun 2016-06-08 22:21:34 -05:00
wsproxy.py Add support for websocket-proxy 2017-05-18 18:42:05 +08:00