We should explicitly install ceph-selinux when using Ceph Hammer
Bug #1626926 reported by
Giulio Fidente
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tripleo |
Invalid
|
Undecided
|
Unassigned | ||
Mitaka |
Fix Released
|
Medium
|
Giulio Fidente |
Bug Description
The Ceph Jewel packages pull in ceph-selinux as a dependency but the Ceph Hammer packages do not.
Yet from 0.94.3 Ceph Hammer can run in enforcing mode as well, so we should explicitly add ceph-selinux to the overcloud image packages for Mitaka (Newton works with Jewel)
Changed in tripleo: | |
status: | New → Invalid |
To post a comment you must log in.
Reviewed: https:/ /review. openstack. org/373998 /git.openstack. org/cgit/ openstack/ tripleo- puppet- elements/ commit/ ?id=caed41ba989 fb0b8dfdd061f09 cf844099a1ad25
Committed: https:/
Submitter: Jenkins
Branch: stable/mitaka
commit caed41ba989fb0b 8dfdd061f09cf84 4099a1ad25
Author: Giulio Fidente <email address hidden>
Date: Tue Sep 20 21:53:16 2016 +0200
Install ceph-selinux in overcloud- {controller, cephstorage} images
Latest versions of Ceph/Hammer can work with SELinux in 'enforcing'
mode so we do not default to 'permissive' from change [1]. This
will only work if the 'ceph-selinux' package is installed and while
Ceph/Jewel packages pull it in as a dependency, Ceph/Hammer will
not so we need to list it explicitly.
1. I469f2bd429eba2 3b2010b7380e794 c67b18e7a47
Closes-Bug: 1626926 a54af1a67cb980d 42536940ad0
Change-Id: I5ad512bc3a948b