144 Commits

Author SHA1 Message Date
Juanita-Balaraj
d66fc5b4da CVSS v3 Adoption for OS
Addressed Patch 5 comments
Addressed Patch 4 comments
Fixed typo
Added a note to indicate CentOS is not being scanned as the master branch has Debian which is being scanned
Updated Index
Added Abbreviations
Added Includes File / Index
Fixed merge conflicts

Change-Id: I17a3c3d6e5b545e24f1530dbb3fdec8adc30b26a
Signed-off-by: Juanita Balaraj <juanita.balaraj@windriver.com>
2022-12-18 00:06:52 -05:00
Ron Stone
cf755b146c KubeVirt/CDI introduction
Inital draft guide for KubeVirt introduction
Conditionalize version
Implement patchset 2 review changes
Implement patchset 3 review changes
Resolve merge conflict
Implement patchset 4 review changes

Story: 2010466

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I57a16fca9b78992b249a1aa04e6b12893c94fe9f
2022-12-16 19:32:48 -05:00
Zuul
6954fb9e9c Merge "Generic CentOS > Debian updates" 2022-12-16 21:48:10 +00:00
Ron Stone
0627a88887 Generic CentOS > Debian updates
Generic changes related to distribution switch-over
Additional updates

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I35509d61e01c1f18437435ae16fdaad1dbd58dbb
2022-12-15 21:14:05 +00:00
Zuul
c78bdd56a8 Merge "Updated commands in "Configure Container-backed Remote CLIs and Clients"" 2022-12-15 17:54:08 +00:00
Juanita-Balaraj
fac1e4ee5b Updated commands in "Configure Container-backed Remote CLIs and Clients"
Modified text based on Patchset 1 comments

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Id673631b36e40a51c55902bb73cb585931962fe5
2022-12-14 19:43:26 -05:00
Zuul
62b1265de3 Merge "Update Pod Security Admission Controller for k8s 1.24" 2022-12-14 21:04:25 +00:00
Elaine Fonaro
bfa44b173a Support for reader role: creation of a new doc
Minor grammar fixes.
Updated the commands line to use the standard ~(keystone_admin)]$.
Minor text updates.
Created the Keystone Account Roles doc.
Updtaded the doc toctree to add a new file.

Story: 2010149
Task: 46908

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I61f79ee8d5dca3410c8e5f155b8e820305176248
2022-12-09 10:17:32 -03:00
Zuul
1a7cc09e6f Merge "Updated CN to "CN=registry.local" (r6, dsr6, r7, dsr7)" 2022-12-07 21:20:32 +00:00
Elisamara Aoki Goncalves
a8ca207890 Update Pod Security Admission Controller for k8s 1.24
Update k8s version.
Remove technology preview.
Fixed typos.

Story: 2010301
Task: 46748

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: If7fcb253090975576994a7923b5c7500a184bbb0
2022-12-07 18:05:50 -03:00
Zuul
3774dbf685 Merge "Updated OIDC service parameter names" 2022-11-30 12:48:13 +00:00
Zuul
58b8df70eb Merge "Use control-plane label for nodeSelector and Tolerations" 2022-11-30 12:35:25 +00:00
Zuul
53093907a3 Merge "Revert "Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)"" 2022-11-28 17:18:11 +00:00
Elaine A Fonaro Antonio
eebc398a50 Revert "Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)"
This reverts commit 12d96861c993050c2e4f98453cfd06d8a4c74688.

Reason for revert: During the latest testing on 22.12, the secret will not create automatically. This mean that the manual command for the secret creation needs to be maintained. Based on this comment, the update for 22.12 needs to be reverted.

Change-Id: I68fa20e0f712abf7ab2247fa66b9f9c40b3f6f7b
2022-11-24 16:29:13 +00:00
Boovan Rajendran
a5a3205277 Use control-plane label for nodeSelector and Tolerations
Comments pertaining to the Stx 8.0 Release Notes in this Gerrit review
will be addressed by Juanita in this story.

Story: 2010441
Task: 46867

Upstream has deprecated 'node-role.kubernetes.io/master'
to use 'node-role.kubernetes.io/control-plane' in k8s 1.24.

Platform and applications need to be updated to use 'control-plane'
with nodeSelector/Tolerations so we may upgrade from 'master'.

This updates pod nodeSelector to use
'node-role.kubernetes.io/control-plane' instead of
'node-role.kubernetes.io/master'.

This updates pod Tolerations to support both:
- 'node-role.kubernetes.io/master'
- 'node-role.kubernetes.io/control-plane'

This commit updates the documentation examples to reflect the above specified changes.

This r8-0-release-notes-6a6ef57f4d99.rst topic has been created to only address updates in Line 745 to 747.

Story: 2010301
Task: 46670

Signed-off-by: Boovan Rajendran <boovan.rajendran@windriver.com>
Change-Id: I1722a025664c70f78a21fdc02fd7750935ef2bc4
2022-11-23 16:15:55 +00:00
Juanita-Balaraj
35021e03fe Updated CN to "CN=registry.local" (r6, dsr6, r7, dsr7)
Closes-Bug:1997489

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Ia119e8d8cf8db3a277b04cf3620f68129707f4dd
2022-11-22 21:11:29 +00:00
Elaine Fonaro
0f57542f81 Updated OIDC service parameter names
- Added a note about historical service parameters for OIDC.

- Renamed the parameters to have dashes instead of underscores.

- Removed occurrences of "\" before "-".

Story: 2009766
Task: 46855

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I47e5ab3c689184bdec20b39b2a00bf999ac5706a
2022-11-18 16:02:05 -03:00
Ron Stone
c3444e384d Implement alarm parsing
Configure tox+content to fetch event and convert alarms and logs
to rst for use in build.
Handle non-existant tmp dir in zuul builds
Add static events.yaml for CI/CD testingx
Generalize label construction to prevent namespace conflicts
Consume events directly from fm repo (required changes merged)
Update logs template for legibility.
Add clean up for temporary rst files.
Point parser at dynamically downloaded events file
Restore logs template

Note: This review deletes static alarm and log files
Note: This review excludes alarm files from git as they are now
      build-time temp files.
Note: This review uses a static copy of events.yaml to pass tox
      until the dep. below is met. It will need reconfiguration
      at that time.

Depends-On: https://review.opendev.org/c/starlingx/fault/+/863574

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: I0bb8d0a77b9d3cf22b33f8930c569b3e70b7291c
2022-11-18 11:34:27 -05:00
Elaine Fonaro
12d96861c9 Manual ceph-pool-kube-rbd secrect creation step removed (r6,r7,dsR6,dsR7)
Removed the Step 5.5 in Procedure since is not required.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I5af88daf037fdde8d82dbd6dd401af8d1ea1bbbf
2022-11-10 16:29:30 -03:00
Elisamara Aoki Goncalves
f57ff3fb99 Update oidc certificate yaml (r7,dsR7)
Closes-bug: 1994888

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I5018c5acc34ef478c5b768830e0f7ccd5594581d
2022-10-26 16:02:13 -03:00
Joao Victor Portal
362af54d37 Update LDAP playbook doc
Added documentation for optional parameter "user_role" in
"manage_local_ldap_account.yml" playbook.

Story: 2010149
Task: 46351

Depends-on: https://review.opendev.org/c/starlingx/ansible-playbooks/+/857982
Signed-off-by: Joao Victor Portal <Joao.VictorPortal@windriver.com>
Change-Id: I29df15ab403f213e5bd328155ad907251b7b56d6
2022-09-20 10:26:53 -03:00
Elaine Fonaro
47c5410fb1 Required SAN parameter for local registry
(Already Cherry picked in the following reviews:
https://review.opendev.org/c/starlingx/docs/+/857061
https://review.opendev.org/c/starlingx/docs/+/857060

- Reword the "The ``ipAddresses``" sentence.
- Removed the "By default after deployment" note.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: Id013cd2b64d22e1bdc5bb22f36d2b4b47523a873
2022-09-14 20:06:31 +00:00
Elisamara Aoki Goncalves
a1f82d7f99 Required SAN parameter for local registry (r6,r7,dsR6,dsR7)
Added note to clarify floating IPs.
Added MGMT floating IP.
Fixed command.

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Idc27a997b9c451efe3fb19953eee4670fb6a11b5
2022-09-09 18:34:03 -03:00
Zuul
2deec2eac5 Merge "Portieris Server Certificate Renewal Policy (r6,dsR6)" 2022-09-08 20:18:21 +00:00
Elisamara Aoki Goncalves
b5151a0efd Portieris Server Certificate Renewal Policy (r6,dsR6)
Removed contradictory info about certificate renewal

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I1c107cc49953047b2478458eb0a5e11c5514ea2b
2022-08-31 20:09:43 +00:00
Elaine Fonaro
551eb09568 Updated Configure Docker Registry Certificate (r6, dsR6, dsR7)
Updated docker-certificate.yaml and removed "organizations:"

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: I1166d56cb98ec58a67d890fa4e564843c9fe6f2c
2022-08-31 19:15:24 +00:00
Ron Stone
4868e1c226 Spelling and typo fixes
Based on sphinx spellchecker testing/refinement.

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ibfe9b6d7bc8bf044a7fff0ac7e362e4067b17989
2022-08-16 16:19:27 -04:00
Zuul
f6dae88439 Merge "Step to install ssl_ca when installing registry certificate (r6)" 2022-08-08 15:01:58 +00:00
Elisamara Aoki Goncalves
f453d387c9 Step to install ssl_ca when installing registry certificate (r6)
Closes-bug: 1981987

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I072cbc4ec68a7bb17e7cbdeb7a79ae469442befb
2022-08-05 21:42:43 +00:00
Elisamara Aoki Goncalves
097142a6a7 Incorrect public key for signed starlingX 5.0 iso (r6)
Fixed minor editorial issues.

Added sub-section to stx only.

closes-bug: 1980666

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Iae3c70db5882ebc57200e9ce4b516848d45b399f
2022-08-05 15:58:15 -03:00
Ron Stone
cf66f5d279 Armada Deprecation and Replacement
First pass - generic updates only. (command input/output to be done)
Address patchset 1 review comments.
Replace examples using openstack with metrics server
Remove DS app from application-list output
Additional migration to FluxCD (snmp, auditd)
Minor textual change.
Fix merge conflict.
Revert install r5 change.

Story: 2009138
Task: 45238

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Ia40ff45f12ec7b7ffa859e0d8bb5535303870d83
2022-06-29 10:40:56 -04:00
Zuul
245d5bc62d Merge "Support for Pod Security Admission Controller - Tech Preview" 2022-06-28 17:43:29 +00:00
Zuul
3a08123440 Merge "Security Audit Logging of K8S API" 2022-06-28 17:33:35 +00:00
Zuul
e3b7c6cf8d Merge "Debian Tech Preview" 2022-06-28 17:26:23 +00:00
Zuul
e3a5aa8343 Merge "Platform Application Components updates ingress-nginx" 2022-06-28 17:21:12 +00:00
Elisamara Aoki Goncalves
35152799b9 Support for Pod Security Admission Controller - Tech Preview
Added new sections referring to Pod security admission controller

Depends-On: https://review.opendev.org/c/starlingx/docs/+/847094

Story: 2009833
Task: 45631

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Icbd36b28501edf767a96007d066303da2d0609f4
2022-06-27 23:16:41 -03:00
Ron Stone
df8d634fc8 Debian Tech Preview
Draft Debian preview document
Additional placeholders for conditional content.
Add k8s 1.23 only bullet to Limited Scope topic.
rST rendering fixes.
Address patchset 3 review comments.
Additional operational impacts.
Implement patchset 5 review comments.
Reuse PXE config updates DS.
Address patchset 8 review comments.
Additional patching details.
rST formatting fix.
Complete Known Issues topic.
Fix typo in placeholder name.
Make references to Debian GA version generic.
Fix merge conflict.
Remove trailing space.

Story: 2009965
Task: 45617

Signed-off-by: Ron Stone <ronald.stone@windriver.com>
Change-Id: Iac67113dc7f56209637828a2b807cd65669ec583
2022-06-27 13:53:02 -04:00
Oliver
65a9de5869 Kubernetes custom configuration support
- added review comments from Path Set 2
- added review comments for Patch Set 1
- added updates for jira CGTS-34418
Change-Id: I8013e445b52d3222cbfa6a94939f65a576956f95
2022-06-27 11:22:50 -04:00
Zuul
32ca14806a Merge "Security Planning shall support customer expectations" 2022-06-24 18:40:25 +00:00
Zuul
68e6a5e711 Merge "Certificates expiration date information" 2022-06-24 15:45:18 +00:00
Zuul
236a9f7b89 Merge "Added a Warning Note for the Portieris application" 2022-06-24 01:04:52 +00:00
Oliver
73e7f8ef4c Security Planning shall support customer expectations
Epic: Security Planning shall support expectations presented in pre-sales presentations.
Updated with review comments for Patch set 4
Updated with review comments for Patch set 3
Updated with review comments from Patch set 2
Updated with review comments from Patch set 1
Added summaries of items raised in pre-sales presentations

Change-Id: Ic1e458dfd57ad7ab18923f3a1756007ad717efe1
2022-06-23 14:09:03 -04:00
Elisamara Aoki Goncalves
ac3a23e9f2 Security Audit Logging of K8S API
Story: 2009835
Task: 45636

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I9b3994baa1dd9aecd8b75f2c1cc8751c66d3db50
2022-06-23 10:35:27 -03:00
Elaine Fonaro
d5adc43774 Certificates expiration date information
Reword and minor update.

Minor updates.

Added extra information about the Alarms link.

Added a note with references regarding how to obtain Certificates expiration data-period information.

Signed-off-by: Elaine Fonaro <elaine.fonaro@windriver.com>
Change-Id: Ic152d5a57effb89534ce269ca0c6a2a8b7f5b5f2
2022-06-23 09:55:16 -03:00
Elisamara Aoki Goncalves
1e0a190aa6 Platform Application Components updates ingress-nginx
Story: 2009836
Task: 45655

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: I93eb5e8e873c29d01d5311a45c252d481c306243
2022-06-23 09:41:59 -03:00
Zuul
ca28c7b1fe Merge "Playbook for managing local ldap admin user" 2022-06-22 20:35:50 +00:00
Juanita-Balaraj
df4cb6c760 Added a Warning Note for the Portieris application
Portieris application is not supported with k8s 1.22 and 1.23

Signed-off-by: Juanita-Balaraj <juanita.balaraj@windriver.com>
Change-Id: Ie67257b1aac24d9fed74a73155d495724cce4886
2022-06-21 18:21:15 -04:00
Pedro Almeida
25f9cc35db Update cert-manager version to v1 from v1alpha2
Following the cert-manager migration to FluxCD, it was upversioned to
v1.7.1 from v0.41.2, which means we need to update our helm-chart
docs to use v1 instead of v1alpha2.

Closes-Bug: #1978858

Signed-off-by: Pedro Almeida <pedro.monteiroazevedodemouraalmeida@windriver.com>
Change-Id: I79955ed7412c0961b315f3b8a8cabd9dfce88fbf
2022-06-21 10:33:38 -03:00
Elisamara Aoki Goncalves
87fa40f233 Platform Application Components updates cert-manager
Story: 2009837
Task: 45638

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Icd792cc1daea5e2b451f66aa7ac366d627d647d5
2022-06-17 10:46:28 -03:00
Elisamara Aoki Goncalves
b20a6233f2 Platform Application Components updates oidc-dex
Story: 2009838
Task: 45597

Signed-off-by: Elisamara Aoki Goncalves <elisamaraaoki.goncalves@windriver.com>
Change-Id: Ia3a0e3e5308221bc8ad1c66cdbb6b1a6046fc32b
2022-06-13 10:18:12 -03:00