CIS hardening breaks rabbitmq-server nagios statistics check
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack RabbitMQ Server Charm |
Fix Committed
|
Medium
|
DUFOUR Olivier | ||
Jammy |
In Progress
|
Undecided
|
Unassigned |
Bug Description
/var/lib/rabbitmq/ rabbitmq:rabbitmq
/var/lib/
so the
/usr/local/
check fails (/etc/nagios/
1.) why data is owned by root:root, when rabbitmq's home folder (/var/lib/rabbitmq) is owned by rabbitmq:rabbitmq?
2.) when running CIS, that sets the umask to 027. This breaks the ability to read the stats by others.
The /var/lib/
update: this is not required: 3.) also cron.d/
workaround: chown -R rabbitmq:rabbitmq /var/lib/rabbitmq; usermod -aG rabbitmq nagios; vim /etc/cron.
description: | updated |
description: | updated |
Changed in charm-rabbitmq-server: | |
status: | New → Triaged |
importance: | Undecided → Medium |
tags: | added: cis-hardening |
Changed in charm-rabbitmq-server: | |
assignee: | nobody → DUFOUR Olivier (odufourc) |
Fix proposed to branch: master /review. opendev. org/c/openstack /charm- rabbitmq- server/ +/860309
Review: https:/