Page MenuHomeDevCentral

Change default Docker group for nasqueron-dev-docker
ClosedPublic

Authored by DorianWinty on Apr 14 2022, 22:34.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Mar 28, 00:36
Unknown Object (File)
Wed, Mar 27, 19:51
Unknown Object (File)
Wed, Mar 27, 14:41
Unknown Object (File)
Wed, Mar 27, 14:35
Unknown Object (File)
Sat, Mar 23, 02:24
Unknown Object (File)
Fri, Mar 22, 18:40
Unknown Object (File)
Fri, Mar 22, 18:38
Unknown Object (File)
Thu, Mar 21, 00:00
Subscribers
None

Details

Summary

As we provision a group nasqueron-dev-docker for Docker devserver,
we can use it for Docker too instead of the default docker one.

Security implication: members of the nasqueron-dev-docker group
has now root access on the Docker engines hosts.

Ref T1724

Test Plan

salt dwellers state.sls roles/paas-docker/docker/config has correctly
provisioned /etc/docker/daemon.json with expected configuration.

Diff Detail

Repository
rOPS Nasqueron Operations
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

DorianWinty created this revision.

Looks good to me:

1$ salt dwellers state.sls roles/core/users test=True
2[...]
3----------
4 ID: dorianwinty
5 Function: user.present
6 Result: None
7 Comment: User dorianwinty set to be added
8 Started: 13:10:22.882113
9 Duration: 4.353 ms
10 Changes:
11[...]
12----------
13 ID: group_nasqueron-dev-docker
14 Function: group.present
15 Name: nasqueron-dev-docker
16 Result: None
17 Comment: Group nasqueron-dev-docker set to be added
18 Started: 13:10:22.899044
19 Duration: 3.884 ms
20 Changes:
21
22$ salt dwellers state.sls roles/core/users
23
24----------
25 ID: dorianwinty
26 Function: user.present
27 Result: True
28 Comment: New user dorianwinty created
29 Started: 13:11:50.644692
30 Duration: 1018.402 ms
31 Changes:
32[...]
33----------
34 ID: group_nasqueron-dev-docker
35 Function: group.present
36 Name: nasqueron-dev-docker
37 Result: True
38 Comment: New group nasqueron-dev-docker created
39 Started: 13:11:51.679170
40 Duration: 640.928 ms
41 Changes:
42 ----------
43 gid:
44 842
45 members:
46 - dereckson
47 - dorianwinty
48 - sandlayth
49 name:
50 nasqueron-dev-docker
51 passwd:
52 x
53
54# Note: it also removed self local key for /home/sandlayth/.ssh/authorized_keys

dereckson edited the test plan for this revision. (Show Details)
This revision is now accepted and ready to land.Apr 15 2022, 17:59