The Gatekeeper, or a project gating system
Go to file
Jeremy Stanley 19def7045e Safely add Ansible password lookup plugin
Ansible's password lookup plugin can be useful for generating random
passwords, but has other uses which could allow a nefarious user to
create new files or read the contents of existing files outside the
workspace (as long as those paths are writeable or readable by the
user under which Ansible is executing). To that end, short-circuit
and return an error if an untrusted use attempts to escape the
workspace in these ways.

Also increase the wait timeout for the plugins test by 25% (from 4
to 5 minutes) since this change increases the number of jobs in it.

Change-Id: I0e372dda3a0f0f74d9e343c439514317dceb4d24
2019-06-12 15:40:35 +00:00
doc Fix typo in docs 2019-05-29 06:13:22 +02:00
etc Fix indent error for layout.yaml-sample. 2018-06-20 12:20:23 +08:00
playbooks Install latest git-review from PyPI in quickstart 2019-05-20 17:46:33 +00:00
releasenotes/notes Report tenant and project specific resource usage stats 2019-05-29 04:10:08 +00:00
tests Safely add Ansible password lookup plugin 2019-06-12 15:40:35 +00:00
tools Merge "encrypt_secret: display the full_url on error" 2019-05-29 16:17:28 +00:00
web Merge "Revert "web: upgrade react and react-scripts to ^2.0.0"" 2019-05-16 23:04:27 +00:00
zuul Safely add Ansible password lookup plugin 2019-06-12 15:40:35 +00:00
.coveragerc Revert "Revert "Switch to stestr"" 2018-05-17 08:33:40 -07:00
.dockerignore Add web/node_modules to dockerignore 2019-01-27 11:23:45 +01:00
.gitignore Fix ignored but tracked .keep file 2018-12-02 09:12:25 +01:00
.gitreview OpenDev Migration Patch 2019-04-19 19:25:28 +00:00
.mailmap Fix pep8 E127 violations 2012-09-26 14:23:10 +00:00
.stestr.conf Revert "Revert "Switch to stestr"" 2018-05-17 08:33:40 -07:00
.zuul.yaml Increase timeout of zuul-tox-remote 2019-05-17 10:21:48 +02:00
COPYING Update README and add GPL license 2018-03-19 09:25:52 -07:00
Dockerfile Cleanup executor specific requirements 2019-04-04 08:58:04 +02:00
LICENSE Initial commit. 2012-05-29 14:49:32 -07:00
MANIFEST.in manifest: add zuul/ansible and ansible-config.conf 2019-03-18 08:07:00 +00:00
README.rst Update references for opendev 2019-04-24 12:59:17 +00:00
TESTING.rst tox: Integrate tox-docker 2019-04-03 15:05:42 +01:00
bindep.txt Install virtualenv from source 2019-03-16 11:07:58 +01:00
requirements.txt Install virtualenv from source 2019-03-16 11:07:58 +01:00
setup.cfg Cleanup executor specific requirements 2019-04-04 08:58:04 +02:00
setup.py Partial sync with OpenStack requirements. 2013-09-25 15:30:37 -07:00
test-requirements.txt Cap mypy 2018-12-07 15:00:17 -08:00
tox.ini Increase test timeout to 6 minutes 2019-06-12 15:39:41 +00:00

README.rst

Zuul

Zuul is a project gating system.

The latest documentation for Zuul v3 is published at: https://zuul-ci.org/docs/zuul/

If you are looking for the Edge routing service named Zuul that is related to Netflix, it can be found here: https://github.com/Netflix/zuul

If you are looking for the Javascript testing tool named Zuul, it can be found here: https://github.com/defunctzombie/zuul

Getting Help

There are two Zuul-related mailing lists:

zuul-announce

A low-traffic announcement-only list to which every Zuul operator or power-user should subscribe.

zuul-discuss

General discussion about Zuul, including questions about how to use it, and future development.

You will also find Zuul developers in the #zuul channel on Freenode IRC.

Contributing

To browse the latest code, see: https://opendev.org/zuul/zuul To clone the latest code, use git clone https://opendev.org/zuul/zuul

Bugs are handled at: https://storyboard.openstack.org/#!/project/zuul/zuul

Suspected security vulnerabilities are most appreciated if first reported privately following any of the supported mechanisms described at https://zuul-ci.org/docs/zuul/user/vulnerabilities.html

Code reviews are handled by gerrit at https://review.openstack.org

After creating a Gerrit account, use git review to submit patches. Example:

# Do your commits
$ git review
# Enter your username if prompted

Join #zuul on Freenode to discuss development or usage.

License

Zuul is free software. Most of Zuul is licensed under the Apache License, version 2.0. Some parts of Zuul are licensed under the General Public License, version 3.0. Please see the license headers at the tops of individual source files.

Python Version Support

Zuul v3 requires Python 3. It does not support Python 2.

As Ansible is used for the execution of jobs, it's important to note that while Ansible does support Python 3, not all of Ansible's modules do. Zuul currently sets ansible_python_interpreter to python2 so that remote content will be executed with Python 2.