Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-7301

fips task forces reboot if fips status changes

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Normal Normal
    • rhos-18.0.0
    • rhos-18.0.0
    • edpm-ansible
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • ?
    • ?
    • ?
    • ?
    • DFG Security: UC Sprint 97
    • Important
    • Security

      https://github.com/openstack-k8s-operators/edpm-ansible/blob/c0f3080c2c862547029c29aad8686d75e26397b1/roles/edpm_bootstrap/tasks/fips.yml#L62-L66

       

      the fips task in the edpm_bootsrap role

      forces a reboot if the fips status changes

       

      While this is not inteded to be support after the intiall deployment

      if the fips mode is changes as part of a minor update this will force reboot all the
      edpm hosts  regardless of the reboot stragey choosen in the deployment.

       

      this task should not override the reboot strategy, and instead delegate the reboot to a explicit invocation of the os-reboot data plane service.

       

            rhn-gps-alee Ade Lee
            smooney@redhat.com Sean Mooney
            rhos-dfg-security
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: