feature: support for hardening library in designate charm
Bug #1659803 reported by
Tytus Kurek
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Designate Charm |
Triaged
|
Medium
|
Unassigned |
Bug Description
Currently designate charm is missing support for hardening library. As Ubuntu OpenStack reference architecture recommends running ALL services (including non-core services) excluding Nova Compute, Ceph OSD and Neutron Gateway inside of LXD containers, it is impossible to achieve fully hardened OpenStack infrastructure because of this limitation. In order to resolved that, a support for hardening library should be added to designate charm.
P.S.: I am not able to report this bug under https:/
Steps to do this: /bazaar. launchpad. net/~charm- helpers/ charm-helpers/ devel/view/ head:/charmhelp ers/contrib/ hardening/ README. hardening. md
https:/
On the hardening framework itself /github. com/hardening- io (moved to github.com/dev-sec)
https:/
https:/ /github. com/dev- sec dev-sec. io/docs/
http://
OS https:/ /github. com/dev- sec/linux- baseline https:/ /github. com/dev- sec/linux- patch-baseline /github. com/dev- sec/ssh- baseline
SSH https:/
MySQL https:/ /github. com/dev- sec/mysql- baseline
Apache https:/ /github. com/dev- sec/apache- baseline