Page MenuHomeDevCentral

Change default Docker group for nasqueron-dev-docker
ClosedPublic

Authored by DorianWinty on Apr 14 2022, 22:34.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Nov 17, 21:44
Unknown Object (File)
Sun, Nov 17, 21:26
Unknown Object (File)
Thu, Nov 14, 20:47
Unknown Object (File)
Fri, Nov 8, 17:32
Unknown Object (File)
Thu, Nov 7, 23:46
Unknown Object (File)
Tue, Nov 5, 23:45
Unknown Object (File)
Tue, Nov 5, 19:46
Unknown Object (File)
Sat, Nov 2, 22:50
Subscribers
None

Details

Summary

As we provision a group nasqueron-dev-docker for Docker devserver,
we can use it for Docker too instead of the default docker one.

Security implication: members of the nasqueron-dev-docker group
has now root access on the Docker engines hosts.

Ref T1724

Test Plan

salt dwellers state.sls roles/paas-docker/docker/config has correctly
provisioned /etc/docker/daemon.json with expected configuration.

Diff Detail

Repository
rOPS Nasqueron Operations
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

DorianWinty created this revision.

Looks good to me:

1$ salt dwellers state.sls roles/core/users test=True
2[...]
3----------
4 ID: dorianwinty
5 Function: user.present
6 Result: None
7 Comment: User dorianwinty set to be added
8 Started: 13:10:22.882113
9 Duration: 4.353 ms
10 Changes:
11[...]
12----------
13 ID: group_nasqueron-dev-docker
14 Function: group.present
15 Name: nasqueron-dev-docker
16 Result: None
17 Comment: Group nasqueron-dev-docker set to be added
18 Started: 13:10:22.899044
19 Duration: 3.884 ms
20 Changes:
21
22$ salt dwellers state.sls roles/core/users
23
24----------
25 ID: dorianwinty
26 Function: user.present
27 Result: True
28 Comment: New user dorianwinty created
29 Started: 13:11:50.644692
30 Duration: 1018.402 ms
31 Changes:
32[...]
33----------
34 ID: group_nasqueron-dev-docker
35 Function: group.present
36 Name: nasqueron-dev-docker
37 Result: True
38 Comment: New group nasqueron-dev-docker created
39 Started: 13:11:51.679170
40 Duration: 640.928 ms
41 Changes:
42 ----------
43 gid:
44 842
45 members:
46 - dereckson
47 - dorianwinty
48 - sandlayth
49 name:
50 nasqueron-dev-docker
51 passwd:
52 x
53
54# Note: it also removed self local key for /home/sandlayth/.ssh/authorized_keys

dereckson edited the test plan for this revision. (Show Details)
This revision is now accepted and ready to land.Apr 15 2022, 17:59