176 Commits

Author SHA1 Message Date
Zuul
0b7ab1dd08 Merge "Cert-Manager Use for StarlingX Platform Services" 2021-12-14 18:59:14 +00:00
Ron Stone
3e03a0bc82 Cert-Manager Use for StarlingX Platform Services
Initial draft procedures.
Resolve merge conflicts.
Incorporate patchset 1 review comments.
Incorporate patchset 2 review comments.
Incorporate patchset 3 review comments.
Incorporate patchset 4 review comments. Open questions for J. Sun to be addressed.
Incorporate patchset 5 review comments.
Made sample url used in overrides generic.
Incorporate patchset 8 review comments.
Added note about issuer_root_ca recommended by J. Sun.
Incorporate patchset 10 review comments.
Fix formatting issue in output.
Incorporate patchset 12 review comments.

Story: 2007361
Task: 42625

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I5a73f902902acc02baccb92995f696a4b19fb773
2021-12-14 11:30:07 -05:00
Elisamara Aoki Goncalves
ee2848e5fa Updates on K8S Root CA Certificate managed by cert-manager
Updated output

Editorial fixes

Merged sections

Fixed typos and indentation

Updated sections titles

Reordered sections in index

Fixed minor grammar issues

Added alarms exception

Described syntax of subject and expiry_date in example

Added references

Replaced K8s for Kubernetes

Story: 2008675
Task: 42625

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I178fe9747c558d13c05b5cf61271fcaff59f6c26
2021-12-13 01:33:32 -03:00
Zuul
abc3bfa93a Merge "Updated Controller Swact commands" 2021-12-09 19:05:31 +00:00
Juanita-Balaraj
22ca60110f Updated Controller Swact commands
Updated Patchset 1 comments
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: If33da881a4dcc16cc3366e4361fd4d6247192ace
2021-12-09 18:43:49 +00:00
Zuul
cb8e03861a Merge "Service parameters deprecated and not being used by puppet manifests" 2021-12-08 22:14:45 +00:00
Zuul
bce970450d Merge "Separate CA for etcd" 2021-12-08 22:09:30 +00:00
Elisamara Aoki Goncalves
483a8196d6 Service parameters deprecated and not being used by puppet manifests
Applied formatting changes

Closes-bug: 1950490

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Iaae1f1d93cc2c3be993781b0d1250b4214148d16
2021-12-07 17:51:59 -03:00
Zuul
72f8fab056 Merge "Add a note for remotecli section when the https is enabled on the system" 2021-12-06 18:59:50 +00:00
Ron Stone
ecfd58375d Add a note for remotecli section when the https is enabled on the system
Added said note as a prereq.
Cleaned up some incidental formatting errors.
Incorporated patchset 1 review comments.
Incorporated patchset 2 review comments.
Incorporated patchset 3 review comments.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I0e2096eb999e2a156d82680e340f769cf33acdd8
2021-12-06 07:08:10 -05:00
Elisamara Aoki Goncalves
738cb1e463 Separate CA for etcd
Removed note and changed place of the new text

Fixed certificates expiration date

Fixed certificate name

Added certificate validity to a note

Rewrote sentence to make content more clear

Story: 2008833
Task: 43600

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ibd1fe52eb4e014217b8d36e4ab3761cdbe8a71d5
2021-11-30 21:03:40 +00:00
Zuul
22359d5bd9 Merge "Alarm Expiring or Expired Certificates" 2021-11-29 20:06:23 +00:00
Zuul
67880814b0 Merge "Removed lock/unlock the controllers and subclouds after the keystone admin password change." 2021-11-26 17:52:52 +00:00
Ron Stone
52b70f81c2 Alarm Expiring or Expired Certificates
Added topic on new expiring/expired cert alarms.
Added 2x alarms to 500 series alarms messages page. NB. Details need to be confirmed.
Minor update for clarity around use of kubernetes edit ...
Added sample fm output
Updtes to alarm definitions based on events.yaml
Incorporated (Word) updates from Greg W.
Patchset 4 review updates.
Patchset 5 review updates.
Fixed merge conflict in sec/kub/index
Patchset 7 review updates.
Patchset 8 review update (note about cert expiry check frequency)

Story: 2008946
Task: 43568

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ifeeba7484e49abcaf2d1ad2afc9afc876d479ded
2021-11-26 11:09:14 -05:00
Juanita-Balaraj
728b29af8e Removed lock/unlock the controllers and subclouds after the keystone admin password change.
Story: 2009194
Task: 43599

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I458b7b3fc0555df851e38e3ab2fa16c25004ac6f
2021-11-25 16:07:21 +00:00
Elisamara Aoki Goncalves
495c9e9427 Platform keystone password rule configuration
Applied minor fixes

Applied editorial fixes

Story: 200984
Task: 43720

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I80b0996b7d19c61630542ccd3b1316967d74366c
2021-11-23 10:28:19 -03:00
Zuul
cd30f7da83 Merge "Auditd Support in StarlingX" 2021-11-18 14:05:51 +00:00
Juanita-Balaraj
74c49fc9a0 Auditd Support in StarlingX
Updated Patchset 4 comments
Updated Patchset 3 comments
Updated Patchset 2 comments
Updated patchset 1 comments
Story: https://storyboard.openstack.org/#!/story/2008849
Task: 43567

The Linux Auditing System containerized solution for StarlingX helps system administrators track security violation events based on pre-configured audit rules.

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I04a1f4c37fea5c43f9d1f7266118b9d636647328
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
2021-11-15 21:27:04 +00:00
Elisamara Aoki Goncalves
4d8775ca61 Updates on Certificate Management (pick)
Removed rst substitution from tables and inline markups.

Updated table and reestructured sections in the overview.

Fixed issues, reworded paragraphs, changed titles.

Deleted unnecessary sections, added a new item to section and fixed editorial issues.

Fixed editorial and formatting issues.

Fixed more editorial and formatting issues.

Fixed formatting and editorial issues.

Added command line.

Fixed command line.

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I69874db16c76d5aceac706f2b8033771780500ca
2021-11-09 17:54:11 -03:00
Ron Stone
d777022a6e fix reference (pick)
Correct markup on :ref: that was exposed to HTML

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ie1ea420b41e4f56c9658fb2eb06649a5409d37eb
2021-11-05 12:46:38 +00:00
Zuul
d8883ef1cf Merge "Fix usertask images (pick)" 2021-11-02 21:07:30 +00:00
Juanita-Balaraj
265d96bed1 Fixed \_ as the output was not rendering correctly (pick r5 updates only)
Fixed Patchset 4 comments
Fixed Patchset 3 comments and added additional updates
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I7482afc3a90bbdc94b6ecd8b6ac39d831b8a45db
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
2021-11-02 11:27:15 -04:00
Ron Stone
749a8b7535 Fix usertask images (pick)
Image location not readable in DS builds. Moved under kubernetes
Build cannot read image geometry metadata, causing :scale: option to fail. Removed.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I526e798bc22efc7efb03b81392825bb3ea9504f0
2021-11-02 14:45:02 +00:00
Zuul
c8f3cc1b05 Merge "Remove instructions to delete secret resource" 2021-10-29 19:32:23 +00:00
Zuul
79a1a6c280 Merge "DEX github 404 error (pick)" 2021-10-26 12:04:45 +00:00
Zuul
891a1784aa Merge "Fix external link-404" 2021-10-26 11:56:36 +00:00
Zuul
46eeaa54ee Merge "Updated references in "Manage Keystone Accounts" To be cherry picked to stx 5.0 Added references in additional topics" 2021-10-26 11:55:50 +00:00
Ron Stone
48b10b81e2 DEX github 404 error (pick)
Updated stale external link in Sec. doc.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: If5d98e321b9d5a998d70a8bbe4a653102b9e1acf
2021-10-25 16:33:58 +00:00
Ron Stone
8ba77ddbe2 Fix external link-404
Removed escape characters from href and anchor text.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I5f4b54eeedad59d5a32c9d4d7ed2c16e1250b426
2021-10-25 07:43:30 -04:00
Juanita-Balaraj
8ff5c131f8 Updated references in "Manage Keystone Accounts"
To be cherry picked to stx 5.0
Added references in additional topics

Updated review comments
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I9bb9ad3d51938c6714320371e506eecb3e1232e1
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
2021-10-22 21:42:22 +00:00
Zuul
2a57218aad Merge "Multiple Trusted CA validation" 2021-10-21 13:26:46 +00:00
Ron Stone
d6a9a0924b Kub. dashboard port-update
Changed Kubernetes dashboard port from 30000 > 32000.
Added Dashboard and VIM ports to Dist. Cloud port list.
Additional ports for VIM and vim-webserver.
Patchset 3 review updates.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I1ea1cf26ea3562bd38917207576ff207e6a7d092
Signed-off-by: Ron Stone <ronald.stone@windriver.com>
2021-10-19 10:38:38 -04:00
Ron Stone
384ecb97e4 Remove instructions to delete secret resource
Instructions removed for Vault and Portieris
Added command to remove Vault

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Idbf6625751a739181c4a0ec5d9161dcfc881d0f8
2021-10-18 12:46:37 +00:00
Ron Stone
5a6d92789c Multiple Trusted CA validation
Update to reflect handling of expired certificates.
Incorporated patchset1 review comments.
Incorporated patchset2 review comments.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I84de3ae0b37b949005d5ef306830a676e3eb8877
2021-10-14 12:26:46 +00:00
Juanita-Balaraj
1b2c274e17 Added new topic with Utility script added to display certificates installed on a system
updated Patchset 5 comments
Updated Patchset 4 comments
Updated Patchset 1 comments
Story: https://storyboard.openstack.org/#!/story/2009190
Task:  43396

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I82bcb12060cfa0c0d4ed26b352d4d5391f66aa91
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
2021-09-27 17:10:56 -04:00
Ron Stone
98d01b5049 TOC structure changes
Conditionalized use of "Contents" heading in Kubernetes and
OpenStack subindexes.
Make "Contents" a common include, overwritable per book
Conditionally pull in kubernetes and OpenStack descriptions from
each book index to kubernetes/index and openstack/index for partner
use
Deleted index.rs1 topics from DITA import

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I857a1dbb567a0bf609b449e8260b2f8801a339fb
Signed-off-by: Ron Stone <ronald.stone@windriver.com>
2021-09-17 11:22:40 -04:00
Juanita-Balaraj
b0c38784b5 Added --reuse-values to the "system helm-override-update" command
Updated Patchset 1 comments
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I75253277515425e9b933686635a62e3f63141e93
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
2021-07-21 19:46:45 -04:00
egoncalv
c12cf2bc59 Replaced relase version to nn.nn
Solved building and merge conflict problem.

Signed-off-by: egoncalv <elisamaraaoki.goncalves@windriver.com>
Change-Id: I9272fa6246bd60ace6a5f7ba64fdb4181b1e4721
2021-06-14 20:16:28 -03:00
Zuul
eebdcdebf1 Merge "Certificate Limitation" 2021-06-14 20:34:22 +00:00
Zuul
300e30a4d1 Merge "Updated Cloud Platform Container Images" 2021-06-14 19:31:28 +00:00
Juanita-Balaraj
7063289b01 Updated Cloud Platform Container Images
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I8d40d7132359c3a86884fd0227fca756a6961147
2021-06-11 18:19:53 -04:00
egoncalv
cd1f0e68ff Inclusive Language Updates
Patch 1: Worked on Bart and Mary's comments.

Patch 2: Worked on Bart's comments.

Signed-off-by: egoncalv <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ida78101e923dbce32a1c17ba45becb4b62f17c4d
2021-06-11 17:18:40 -03:00
Ron Stone
792b7de1ef Certificate Limitation
Updated container based remote CLI note

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ia4c2286c005226229f40ad60c3908e42ffcad17d
2021-06-10 13:28:50 -04:00
Zuul
49d28c098a Merge "Configure Remote Helm v2 Client" 2021-06-09 11:55:00 +00:00
Adil
b36ac7a967 Configure Remote Helm v2 Client
-Helm v2 content added

Added content from email in Jira

Fixed line error

This review is related to: https://review.opendev.org/c/starlingx/docs/+/783891
  This was merged

New review with corrections:

Signed-off-by: Adil <mohamed.adilassakkali@windriver.com>
Change-Id: I0d7c639efd3a4964853959963567e1a15e0f2ce8
2021-06-08 09:35:51 -03:00
egoncalv
ff0c830115 Remote CLI: Client container doesn't trust the CA.
Added note.

Patch 1: Worked on Ayyappa comments.

Patch 2: Worked on Greg's comments.

Patch 3: Worked on Mary's comments.

Patch 4: Fixed typo.

Signed-off-by: egoncalv <elisamaraaoki.goncalves@windriver.com>
Change-Id: I27aab71790f8f21099189b8c2557627203186e9d
2021-06-08 09:07:29 -03:00
Zuul
7ce412da79 Merge "Added a Note to the topic, "Configure Container-backed Remote CLIs"" 2021-06-07 12:44:03 +00:00
Juanita-Balaraj
294f22dd0d Added a Note to the topic, "Configure Container-backed Remote CLIs"
Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: I375893638a445b3d57162e3f2b05c472ca3f8141
2021-06-04 22:09:16 -04:00
Zuul
a659fe688a Merge "Protocols update and renaming" 2021-06-04 17:10:54 +00:00
Zuul
de8e901aa8 Merge "Node Management Guide Global Pass Upgrades" 2021-06-04 17:06:51 +00:00