176 Commits

Author SHA1 Message Date
Juanita Balaraj
cb0245cfab Added RSA Key length (dsr8)
Modified the note to include <the certificate file>
Removed trailing spaces and fixed Patchset 7 comments
Updated Patchset 6 comments and removed the word platform
Fixed formatting issues
Updated Patchset 4 comments
Added additional notes in multiple topics listed in the review
Updated the Security / Upgrade Guide with a note
Change-Id: If0a88e88268b2a4540b6abf97bc7b5ca9049747c
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>

Change-Id: I5686cda10f4ac9b184f5ac1e6ceec003b09155d2
2023-06-28 04:44:19 +00:00
Ron Stone
eeb229345c Extract Secure Boot Cert from ISO (dsR8,dsR7,dsR6,r5)
Add include placeholder for DS addition.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I73514b347868e5a7b0b14caec79c58c342fb7055
2023-06-07 17:15:49 +00:00
Zuul
046e72de21 Merge "Front-proxy-client and front-proxy-ca certificates are not documented (r8,dsR8)" 2023-05-18 20:47:58 +00:00
Elisamara Aoki Goncalves
10fd3a0bb8 Front-proxy-client and front-proxy-ca certificates are not documented (r8,dsR8)
Add front-proxy-client and front-proxy-ca certificates to the list.

Closes-bug: 2019959

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ie940da7352e80322c9d462c7cc219ceec879597d
2023-05-17 17:29:33 -03:00
Juanita-Balaraj
b668350000 Updated the migration-inventory.yaml file (r7, dsr7, r8, dsr8)
Changed Canada to CA

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I35322c9523dba4c94eb8fa5ddaaf2542e08eea57
2023-05-17 19:58:40 +00:00
Zuul
7912486560 Merge "Changes for OS Level Access Controls with AppArmor (dsR8)" 2023-05-10 19:55:44 +00:00
Elisamara Aoki Goncalves
a1e1bfb155 Platform Application Components Up-version - Portieris (dsR8)
Add missing registryk8s-registry
Fix conflict.
Add icr-registry and missing ghcr-registry

Story: 2010394
Task: 47866

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Iddf5b5c807d1ae1ca5ea342ccce53cc9da2f576e
2023-05-05 11:10:41 -03:00
Elisamara Aoki Goncalves
3af4934d2b Changes for OS Level Access Controls with AppArmor (dsR8)
Fix conflict.

Story: 2010310
Task: 47841

Depends on https://review.opendev.org/c/starlingx/docs/+/877844

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I733cf26aa801fc28e42b8a0bbded50cf788f1638
2023-05-02 15:20:45 -03:00
Zuul
4d531cedb4 Merge "AppArmor Support (dsR8)" 2023-04-26 20:11:56 +00:00
Elisamara Aoki Goncalves
ace0287d7a AppArmor Support (dsR8)
Story: 2010310
Task: 47620

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I97065a0d0c345bb32663e1ff631c5c4ca524231d
2023-04-25 15:53:17 -03:00
Zuul
6059b20167 Merge "Vault updates (r8,dsR8)" 2023-04-19 20:31:06 +00:00
Ron Stone
f125a8b892 Remove spurious escapes (r8,dsR8)
This change addresses a long-standing issue in rST documentation imported from XML.
That import process added backslash escapes in front of various characters. The three
most common being '(', ')', and '_'.
These instances are removed.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Id43a9337ffcd505ccbdf072d7b29afdb5d2c997e
2023-03-01 11:19:04 +00:00
Ron Stone
ec64850b57 Vault updates (r8,dsR8)
Add links to the Vault developer documentation.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I8884a38618f22937afbde328fca3f5e193802dc1
2023-02-22 07:23:52 -05:00
Ron Stone
810927b055 Replace container tags
Replace hard coded tag values with subsitutions

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I76aa5e8dc1870f5496b303f482a651d524fea3ce
2023-01-30 10:19:18 -05:00
Elaine Fonaro
833451bd9f Fix errors in the proc. to config. HTTPS and use remote CLI with it
r6/r7 Updates: https://review.opendev.org/c/starlingx/docs/+/869828

- Back "organizations" and "ABC-Company" from command.
- Fixed the code block structure.
- Replaced "-o=jsonpath='{.data.ca\.crt}'" command.
- Removed "organizations" and "ABC-Company" from command.
- Added the "touch ${OUTPUT_FILE}" command.
- Fixed the "platform -r admin_openrc.sh" command.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: Icd09250e48e89b25157b5db2afac01658317c501
2023-01-25 21:00:49 +00:00
Elisamara Aoki Goncalves
b69f425279 Add warning about required manual action (r5,r6,r7,dsR6,dsR7)
Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I9d753623b110c9a58cd4baa502455e5dbb3d8a3d
2023-01-09 12:37:31 -03:00
Zuul
27e9887a36 Merge "Add a note users to lock/unlock controller nodes after installing a ssl_ca" 2022-12-21 14:58:08 +00:00
Zuul
89c3d50bcb Merge "Update KubeVirt Windows VM" 2022-12-21 14:12:18 +00:00
Ron Stone
e8cbaad48d Update KubeVirt Windows VM
Add ClusterRoleBinding to YAML declaration
Remove annotation
Add EOF
Patchset 2 update (remove ClusterRoleBinding)
Patchset 2 update (edit Set up remote management of VMs)
Patchset 2 update (add secret to other ClusterRoleBindings)
Patchset 5 updates
Patchset 6 updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I11e63f97c82f4cb3e92403e8a8423d892e3160a3
2022-12-21 07:19:46 -05:00
Zuul
2f15495466 Merge "Fix formatting" 2022-12-20 16:34:52 +00:00
Zuul
3c600d0d5a Merge "CVSS v3 Adoption for OS" 2022-12-20 16:16:45 +00:00
Zuul
281ae61bfa Merge "High Security Vulnerability Document Updates (r6, r6ds, r7, r7ds)" 2022-12-20 15:07:28 +00:00
Ron Stone
cb67e1c0dc Fix formatting
Correct indentation in note.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Idbfca945b6007abb0becdc506522ef0d9e7b618f
2022-12-20 07:12:05 -05:00
Elaine Fonaro
cfed9ee0dc Add a note users to lock/unlock controller nodes after installing a ssl_ca
- Added a note for lock/unlock controler node.
- Added a reference for installing a root CA.

Closes-bug: 1995145

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I293ecc19348308e60da7f5922d169c455b895576
2022-12-19 21:33:33 -03:00
Juanita-Balaraj
6fe81edbcd LDAP Linux user account lock messages are not displayed
Fixed merge conflicts
Removed Debian from the updates
Removed CentOS update
Modified the note in "Local LDAP Linux User Accounts"

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I39ee05afa87c777266df739daec323a6a4e59d06
2022-12-19 18:09:14 -05:00
Zuul
2415b07806 Merge "SSH integration with remote WAD" 2022-12-19 19:09:47 +00:00
Zuul
c1dbf8ac53 Merge "Container version updates" 2022-12-19 16:20:12 +00:00
Zuul
5a446e5e7e Merge "Create OpenLDAP certificate on bootstrap" 2022-12-19 16:06:19 +00:00
Elisamara Aoki Goncalves
0d17a1d482 SSH integration with remote WAD
Create section SSSD Support
Add SSSD to abbrev list
Fix commands
Add back line 45 to 47
Fix typos
Change section name and index
Reword and remove unnecessary sub-sections
Add examples
Remove duplicated SSSD
Add note

Story: 2009834
Task: 46547

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ibf891aa076319c78e2e19e862d2601047312f174
2022-12-19 12:55:56 -03:00
Juanita-Balaraj
d66fc5b4da CVSS v3 Adoption for OS
Addressed Patch 5 comments
Addressed Patch 4 comments
Fixed typo
Added a note to indicate CentOS is not being scanned as the master branch has Debian which is being scanned
Updated Index
Added Abbreviations
Added Includes File / Index
Fixed merge conflicts

Change-Id: I17a3c3d6e5b545e24f1530dbb3fdec8adc30b26a
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2022-12-18 00:06:52 -05:00
Ron Stone
cf755b146c KubeVirt/CDI introduction
Inital draft guide for KubeVirt introduction
Conditionalize version
Implement patchset 2 review changes
Implement patchset 3 review changes
Resolve merge conflict
Implement patchset 4 review changes

Story: 2010466

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I57a16fca9b78992b249a1aa04e6b12893c94fe9f
2022-12-16 19:32:48 -05:00
Juanita-Balaraj
e3bbf0564a High Security Vulnerability Document Updates (r6, r6ds, r7, r7ds)
Updated Patchset 7 comments
Fixed merge conflicts
Updated review comments from Patchset 4
Closes-Bug:1997909
Fixed build errors
Greg to review and provide inputs

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I2f630104813210f160fa56e7af7e9754a6d9236a
2022-12-16 18:04:58 -05:00
Zuul
6954fb9e9c Merge "Generic CentOS > Debian updates" 2022-12-16 21:48:10 +00:00
Ron Stone
28e283b1c3 Container version updates
Container version updates for r8.
Add partial vran updates.
Resolve merge conflict.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Iee462f3d3a9c62a5e526f12ab65cb7827d19e00b
2022-12-16 16:21:17 -05:00
Ron Stone
0627a88887 Generic CentOS > Debian updates
Generic changes related to distribution switch-over
Additional updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I35509d61e01c1f18437435ae16fdaad1dbd58dbb
2022-12-15 21:14:05 +00:00
Zuul
c78bdd56a8 Merge "Updated commands in "Configure Container-backed Remote CLIs and Clients"" 2022-12-15 17:54:08 +00:00
Juanita-Balaraj
fac1e4ee5b Updated commands in "Configure Container-backed Remote CLIs and Clients"
Modified text based on Patchset 1 comments

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Id673631b36e40a51c55902bb73cb585931962fe5
2022-12-14 19:43:26 -05:00
Zuul
62b1265de3 Merge "Update Pod Security Admission Controller for k8s 1.24" 2022-12-14 21:04:25 +00:00
Elaine Fonaro
bfa44b173a Support for reader role: creation of a new doc
Minor grammar fixes.
Updated the commands line to use the standard ~(keystone_admin)]$.
Minor text updates.
Created the Keystone Account Roles doc.
Updtaded the doc toctree to add a new file.

Story: 2010149
Task: 46908

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I61f79ee8d5dca3410c8e5f155b8e820305176248
2022-12-09 10:17:32 -03:00
Zuul
1a7cc09e6f Merge "Updated CN to "CN=registry.local" (r6, dsr6, r7, dsr7)" 2022-12-07 21:20:32 +00:00
Elisamara Aoki Goncalves
a8ca207890 Update Pod Security Admission Controller for k8s 1.24
Update k8s version.
Remove technology preview.
Fixed typos.

Story: 2010301
Task: 46748

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: If7fcb253090975576994a7923b5c7500a184bbb0
2022-12-07 18:05:50 -03:00
Zuul
3774dbf685 Merge "Updated OIDC service parameter names" 2022-11-30 12:48:13 +00:00
Zuul
58b8df70eb Merge "Use control-plane label for nodeSelector and Tolerations" 2022-11-30 12:35:25 +00:00
Zuul
53093907a3 Merge "Revert "Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)"" 2022-11-28 17:18:11 +00:00
Elaine A Fonaro Antonio
eebc398a50 Revert "Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)"
This reverts commit 12d96861c993050c2e4f98453cfd06d8a4c74688.

Reason for revert: During the latest testing on 22.12, the secret will not create automatically. This mean that the manual command for the secret creation needs to be maintained. Based on this comment, the update for 22.12 needs to be reverted.

Change-Id: I68fa20e0f712abf7ab2247fa66b9f9c40b3f6f7b
2022-11-24 16:29:13 +00:00
Boovan Rajendran
a5a3205277 Use control-plane label for nodeSelector and Tolerations
Comments pertaining to the Stx 8.0 Release Notes in this Gerrit review
will be addressed by Juanita in this story.

Story: 2010441
Task: 46867

Upstream has deprecated 'node-role.kubernetes.io/master'
to use 'node-role.kubernetes.io/control-plane' in k8s 1.24.

Platform and applications need to be updated to use 'control-plane'
with nodeSelector/Tolerations so we may upgrade from 'master'.

This updates pod nodeSelector to use
'node-role.kubernetes.io/control-plane' instead of
'node-role.kubernetes.io/master'.

This updates pod Tolerations to support both:
- 'node-role.kubernetes.io/master'
- 'node-role.kubernetes.io/control-plane'

This commit updates the documentation examples to reflect the above specified changes.

This r8-0-release-notes-6a6ef57f4d99.rst topic has been created to only address updates in Line 745 to 747.

Story: 2010301
Task: 46670

Signed-off-by: Boovan Rajendran <boovan.rajendran@windriver.com>
Change-Id: I1722a025664c70f78a21fdc02fd7750935ef2bc4
2022-11-23 16:15:55 +00:00
Juanita-Balaraj
35021e03fe Updated CN to "CN=registry.local" (r6, dsr6, r7, dsr7)
Closes-Bug:1997489

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Ia119e8d8cf8db3a277b04cf3620f68129707f4dd
2022-11-22 21:11:29 +00:00
Elaine Fonaro
0f57542f81 Updated OIDC service parameter names
- Added a note about historical service parameters for OIDC.

- Renamed the parameters to have dashes instead of underscores.

- Removed occurrences of "\" before "-".

Story: 2009766
Task: 46855

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I47e5ab3c689184bdec20b39b2a00bf999ac5706a
2022-11-18 16:02:05 -03:00
Ron Stone
c3444e384d Implement alarm parsing
Configure tox+content to fetch event and convert alarms and logs
to rst for use in build.
Handle non-existant tmp dir in zuul builds
Add static events.yaml for CI/CD testingx
Generalize label construction to prevent namespace conflicts
Consume events directly from fm repo (required changes merged)
Update logs template for legibility.
Add clean up for temporary rst files.
Point parser at dynamically downloaded events file
Restore logs template

Note: This review deletes static alarm and log files
Note: This review excludes alarm files from git as they are now
      build-time temp files.
Note: This review uses a static copy of events.yaml to pass tox
      until the dep. below is met. It will need reconfiguration
      at that time.

Depends-On: https://review.opendev.org/c/starlingx/fault/+/863574

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I0bb8d0a77b9d3cf22b33f8930c569b3e70b7291c
2022-11-18 11:34:27 -05:00
Elaine Fonaro
12d96861c9 Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)
Removed the Step 5.5 in Procedure since is not required.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I5af88daf037fdde8d82dbd6dd401af8d1ea1bbbf
2022-11-10 16:29:30 -03:00