195 Commits

Author SHA1 Message Date
Ngairangbam Mili
d492b8711b Update certificate information for clarity with show-certs.sh output (r8, ds8)
Change-Id: Ie38f65aaa86abbd6b22a5fee38281aa417556cd5
Signed-off-by: Ngairangbam Mili <ngairangbam.mili@windriver.com>
2023-10-18 13:14:34 +00:00
Elisamara Aoki Goncalves
ba01686f7a Fix broken links (dsR8)
Fix and update links.

Change-Id: I868b64a8b347d7746f857543f3a75760954ddee9
Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
2023-10-05 21:27:32 +00:00
Elaine Fonaro
edf05c3460 Input for L3 Firewall for all WRCP Platform Interfaces (dsr8)
- Added information to allow operator firewall customization update for all platform networks.
- Minor updates.
- Editorial fixes.
- Added one  new item in the abbrevs.txt file.
- Minor fix.

Story: 2010591
Task: 48703

Change-Id: I727d7b5412c50e59f97839f62ef03359eff78b81
Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
2023-09-22 11:43:48 +00:00
Juanita Balaraj
98f8b72701 Updated Limitation for IPv6 addresses (r8, dsr8)
Updated the title in the rest file
Shorten filename. Link with very long file name is broken in some URL contexts
such as local builds This change corrects it in local testing but needs
further verification from other contributors.

Linked to: https://review.opendev.org/c/starlingx/docs/+/891913
Change-Id: I3ad7ac655ef46190efa0f4bb88345195333d4030
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2023-08-31 18:32:41 +00:00
Juanita Balaraj
2ac452053c Updated Limitation and Workaround for using IPv6 addresses in Cert management (r8, dsr8)
Updated formatting issues
Included inputs from Gerrit rview https://review.opendev.org/c/starlingx/docs/+/847215; https://review.opendev.org/c/starlingx/docs/+/888578
Updated Patchset 1 comments and added the limitation in
Created Include file to add the Limitation
Change-Id: I59aabd2bc67c4f2820b75ece7f6a0557729adc9e
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2023-08-29 19:26:32 +00:00
Zuul
36532f4bdd Merge "Reformat file (r8, r7, r6. r5, dsR8, dsR7, dsR6)" 2023-08-11 16:15:13 +00:00
Ron Stone
80fe12fbe5 Reformat file (r8, r7, r6. r5, dsR8, dsR7, dsR6)
This file required an editorial scrub. Poorly structured and formatted. Several
instances of uncommented narrative text in code-blocks. Grammer and punct. errors.
Etc.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I3fdb3982b162fdc4ce50d4b034a649d0589648df
2023-08-11 14:01:21 +00:00
Ron Stone
f843d3daa4 HTTPS cert updates
General update to Security/HTTPS and Certificates Management:
- reorganization
- content updates
Implement patchset 1 review comments
Implement patchset 2 review comments

Closes-Bug: 2028184

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Iae75785e479c96751fb50a097eba8ed5e6069e94
2023-07-24 11:51:39 +00:00
Zuul
ed963e3a2d Merge "Update and fix LDAP playbook documentation" 2023-07-20 20:17:45 +00:00
Joao Victor Portal
95a573ddef Update and fix LDAP playbook documentation
Update documentation to reflect the lastest code changes. Some small
fixes were also included.

Closes-Bug: 2024627
Depends-On: https://review.opendev.org/c/starlingx/ansible-playbooks/+/886529
Signed-off-by: Joao Victor Portal <Joao.VictorPortal@windriver.com>
Change-Id: I98c02cb64818e80f5c6d053767e86601e23084e7
2023-07-18 17:30:42 -03:00
Zuul
5bb538f19b Merge "Adding note of PSP removal from the project documentation" 2023-07-18 15:01:30 +00:00
Rahul Roshan Kachchap
f076c3a387 Adding note of PSP removal from the project documentation
Removal of PSP Support as part of k8s 1.25/1.26 transition,
we are adding a note to each page that has pod security policy
contexts from the project doc about its existence in K8S v1.24
and removal from K8S v1.25

Story: 2010590
Task: 48324

Change-Id: Ifefeda7ac181267b66398dbf45af9f6ee1239090
Signed-off-by: Rahul Roshan Kachchap <rahulroshan.kachchap@windriver.com>
2023-07-17 08:35:10 -04:00
Joao Victor Portal
0129f54537 Update Dex image and chart versions
Story: 2010703
Task: 48391

Signed-off-by: Joao Victor Portal <Joao.VictorPortal@windriver.com>
Change-Id: I6d29c71ec6c701a06f9ba47d21092c1b06ca22a2
2023-07-14 14:39:04 -03:00
Zuul
25a52459f9 Merge "Update secure boot doc about StarlingX Debian" 2023-07-12 12:06:38 +00:00
Li Zhou
1e8067d7f9 Update secure boot doc about StarlingX Debian
Add "Build considerations for signing packages for UEFI Secure Boot"
for Debian build, which has been different with Centos build.

Story: 2010643
Task: 47834

Change-Id: I0acbbfa52d8e78ed369ec8f2c9f37eed4dce6a41
Signed-off-by: Li Zhou <li.zhou@windriver.com>
2023-07-11 21:57:55 -04:00
Zuul
58c9782b8e Merge "Added RSA Key length (dsr8)" 2023-06-28 14:37:31 +00:00
Juanita Balaraj
cb0245cfab Added RSA Key length (dsr8)
Modified the note to include <the certificate file>
Removed trailing spaces and fixed Patchset 7 comments
Updated Patchset 6 comments and removed the word platform
Fixed formatting issues
Updated Patchset 4 comments
Added additional notes in multiple topics listed in the review
Updated the Security / Upgrade Guide with a note
Change-Id: If0a88e88268b2a4540b6abf97bc7b5ca9049747c
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>

Change-Id: I5686cda10f4ac9b184f5ac1e6ceec003b09155d2
2023-06-28 04:44:19 +00:00
Zuul
1bdfec3baa Merge "Updated CVSS v3.x" 2023-06-26 21:19:17 +00:00
Juanita Balaraj
13a03e6cd2 Updated CVSS v3.x
Updated patchset 5 comments
Indented Text only
Updated patchset 3 comments
Removed Partner information and only retained information specific to StarlingX
Change-Id: Ibc8da0d9772422ee09fb46759730ada2c1ac12b2
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2023-06-26 19:54:39 +00:00
Elisamara Aoki Goncalves
5fc380397e Ansible playbook command copy/paste has space in it (r8,dsR8)
Closes-bug: 2024368

Change-Id: I5cb98fdceea435ee08b041866f1cf435ba927502
Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
2023-06-19 12:26:32 +00:00
Ron Stone
eeb229345c Extract Secure Boot Cert from ISO (dsR8,dsR7,dsR6,r5)
Add include placeholder for DS addition.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I73514b347868e5a7b0b14caec79c58c342fb7055
2023-06-07 17:15:49 +00:00
Zuul
046e72de21 Merge "Front-proxy-client and front-proxy-ca certificates are not documented (r8,dsR8)" 2023-05-18 20:47:58 +00:00
Elisamara Aoki Goncalves
10fd3a0bb8 Front-proxy-client and front-proxy-ca certificates are not documented (r8,dsR8)
Add front-proxy-client and front-proxy-ca certificates to the list.

Closes-bug: 2019959

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ie940da7352e80322c9d462c7cc219ceec879597d
2023-05-17 17:29:33 -03:00
Juanita-Balaraj
b668350000 Updated the migration-inventory.yaml file (r7, dsr7, r8, dsr8)
Changed Canada to CA

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I35322c9523dba4c94eb8fa5ddaaf2542e08eea57
2023-05-17 19:58:40 +00:00
Zuul
7912486560 Merge "Changes for OS Level Access Controls with AppArmor (dsR8)" 2023-05-10 19:55:44 +00:00
Elisamara Aoki Goncalves
a1e1bfb155 Platform Application Components Up-version - Portieris (dsR8)
Add missing registryk8s-registry
Fix conflict.
Add icr-registry and missing ghcr-registry

Story: 2010394
Task: 47866

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Iddf5b5c807d1ae1ca5ea342ccce53cc9da2f576e
2023-05-05 11:10:41 -03:00
Elisamara Aoki Goncalves
3af4934d2b Changes for OS Level Access Controls with AppArmor (dsR8)
Fix conflict.

Story: 2010310
Task: 47841

Depends on https://review.opendev.org/c/starlingx/docs/+/877844

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I733cf26aa801fc28e42b8a0bbded50cf788f1638
2023-05-02 15:20:45 -03:00
Zuul
4d531cedb4 Merge "AppArmor Support (dsR8)" 2023-04-26 20:11:56 +00:00
Elisamara Aoki Goncalves
ace0287d7a AppArmor Support (dsR8)
Story: 2010310
Task: 47620

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I97065a0d0c345bb32663e1ff631c5c4ca524231d
2023-04-25 15:53:17 -03:00
Zuul
6059b20167 Merge "Vault updates (r8,dsR8)" 2023-04-19 20:31:06 +00:00
Ron Stone
f125a8b892 Remove spurious escapes (r8,dsR8)
This change addresses a long-standing issue in rST documentation imported from XML.
That import process added backslash escapes in front of various characters. The three
most common being '(', ')', and '_'.
These instances are removed.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Id43a9337ffcd505ccbdf072d7b29afdb5d2c997e
2023-03-01 11:19:04 +00:00
Ron Stone
ec64850b57 Vault updates (r8,dsR8)
Add links to the Vault developer documentation.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I8884a38618f22937afbde328fca3f5e193802dc1
2023-02-22 07:23:52 -05:00
Ron Stone
810927b055 Replace container tags
Replace hard coded tag values with subsitutions

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I76aa5e8dc1870f5496b303f482a651d524fea3ce
2023-01-30 10:19:18 -05:00
Elaine Fonaro
833451bd9f Fix errors in the proc. to config. HTTPS and use remote CLI with it
r6/r7 Updates: https://review.opendev.org/c/starlingx/docs/+/869828

- Back "organizations" and "ABC-Company" from command.
- Fixed the code block structure.
- Replaced "-o=jsonpath='{.data.ca\.crt}'" command.
- Removed "organizations" and "ABC-Company" from command.
- Added the "touch ${OUTPUT_FILE}" command.
- Fixed the "platform -r admin_openrc.sh" command.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: Icd09250e48e89b25157b5db2afac01658317c501
2023-01-25 21:00:49 +00:00
Elisamara Aoki Goncalves
b69f425279 Add warning about required manual action (r5,r6,r7,dsR6,dsR7)
Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I9d753623b110c9a58cd4baa502455e5dbb3d8a3d
2023-01-09 12:37:31 -03:00
Zuul
27e9887a36 Merge "Add a note users to lock/unlock controller nodes after installing a ssl_ca" 2022-12-21 14:58:08 +00:00
Zuul
89c3d50bcb Merge "Update KubeVirt Windows VM" 2022-12-21 14:12:18 +00:00
Ron Stone
e8cbaad48d Update KubeVirt Windows VM
Add ClusterRoleBinding to YAML declaration
Remove annotation
Add EOF
Patchset 2 update (remove ClusterRoleBinding)
Patchset 2 update (edit Set up remote management of VMs)
Patchset 2 update (add secret to other ClusterRoleBindings)
Patchset 5 updates
Patchset 6 updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I11e63f97c82f4cb3e92403e8a8423d892e3160a3
2022-12-21 07:19:46 -05:00
Zuul
2f15495466 Merge "Fix formatting" 2022-12-20 16:34:52 +00:00
Zuul
3c600d0d5a Merge "CVSS v3 Adoption for OS" 2022-12-20 16:16:45 +00:00
Zuul
281ae61bfa Merge "High Security Vulnerability Document Updates (r6, r6ds, r7, r7ds)" 2022-12-20 15:07:28 +00:00
Ron Stone
cb67e1c0dc Fix formatting
Correct indentation in note.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Idbfca945b6007abb0becdc506522ef0d9e7b618f
2022-12-20 07:12:05 -05:00
Elaine Fonaro
cfed9ee0dc Add a note users to lock/unlock controller nodes after installing a ssl_ca
- Added a note for lock/unlock controler node.
- Added a reference for installing a root CA.

Closes-bug: 1995145

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I293ecc19348308e60da7f5922d169c455b895576
2022-12-19 21:33:33 -03:00
Juanita-Balaraj
6fe81edbcd LDAP Linux user account lock messages are not displayed
Fixed merge conflicts
Removed Debian from the updates
Removed CentOS update
Modified the note in "Local LDAP Linux User Accounts"

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I39ee05afa87c777266df739daec323a6a4e59d06
2022-12-19 18:09:14 -05:00
Zuul
2415b07806 Merge "SSH integration with remote WAD" 2022-12-19 19:09:47 +00:00
Zuul
c1dbf8ac53 Merge "Container version updates" 2022-12-19 16:20:12 +00:00
Zuul
5a446e5e7e Merge "Create OpenLDAP certificate on bootstrap" 2022-12-19 16:06:19 +00:00
Elisamara Aoki Goncalves
0d17a1d482 SSH integration with remote WAD
Create section SSSD Support
Add SSSD to abbrev list
Fix commands
Add back line 45 to 47
Fix typos
Change section name and index
Reword and remove unnecessary sub-sections
Add examples
Remove duplicated SSSD
Add note

Story: 2009834
Task: 46547

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ibf891aa076319c78e2e19e862d2601047312f174
2022-12-19 12:55:56 -03:00
Juanita-Balaraj
d66fc5b4da CVSS v3 Adoption for OS
Addressed Patch 5 comments
Addressed Patch 4 comments
Fixed typo
Added a note to indicate CentOS is not being scanned as the master branch has Debian which is being scanned
Updated Index
Added Abbreviations
Added Includes File / Index
Fixed merge conflicts

Change-Id: I17a3c3d6e5b545e24f1530dbb3fdec8adc30b26a
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2022-12-18 00:06:52 -05:00
Ron Stone
cf755b146c KubeVirt/CDI introduction
Inital draft guide for KubeVirt introduction
Conditionalize version
Implement patchset 2 review changes
Implement patchset 3 review changes
Resolve merge conflict
Implement patchset 4 review changes

Story: 2010466

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I57a16fca9b78992b249a1aa04e6b12893c94fe9f
2022-12-16 19:32:48 -05:00