Container Infrastructure Management Service for OpenStack
Go to file
Johannes Grassler 8a9e4089aa Fix CVE-2016-7404
This commit is a bare-bones stable/mitaka backport of the fix for
CVE-2016-7404. It only retains

* Permissions for /etc/sysconfig/heat-params inside Magnum
  created instances are tightened to 0600 (used to be 0755).

from the original patch. This was done for two reasons:

* Since stable/mitaka only passes tokens (which expire eventually)
  an attacker would have to gain access to the instance within
  a very short time window (the token expiration time).

* Backporting the remaining changes would have required
  backporting the trusts infrastructure that was only
  completed in stable/newton. This would mean a considerable
  change in the stable/mitaka default behaviour.

Please note, that this change does not apply apply to existing
clusters. They will have to be deleted and rebuilt to benefit
from these changes.

(cherry picked from commit 0bb0d6486d)

Change-Id: I329d29cdcce2225f8aa5b57852e6a37d4f8aaa3e
2017-02-26 14:46:03 +00:00
contrib/templates/example Update Dev Quick-Start links to officail docs 2015-10-05 00:35:46 -07:00
devstack devstack: Comment out some environment dependent neutron settings 2016-03-11 14:32:41 +09:00
doc/source Rename tenant to project in functional test 2016-05-05 11:11:43 -04:00
etc/magnum Moved CORS middleware configuration into oslo-config-generator 2016-03-09 13:02:07 -08:00
magnum Fix CVE-2016-7404 2017-02-26 14:46:03 +00:00
specs Fix Definitions part for container-networking-model.rst 2016-03-02 09:30:09 +09:00
tools Improve tox.ini to easy developer's life 2015-11-03 17:44:38 +08:00
.coveragerc Change ignore-errors to ignore_errors 2015-09-21 14:28:49 +00:00
.gitignore Ignore the generated config file 2016-02-29 14:50:35 -05:00
.gitreview Add a gitreview default target for gerrit for mitaka 2016-03-23 16:08:04 -04:00
.mailmap Initial commit from github (squashed) 2014-11-18 09:23:37 -05:00
.testr.conf Make room for functional tests 2015-04-02 12:25:43 -04:00
CONTRIBUTING.rst Workflow documentation is now in infra-manual 2014-12-05 03:30:45 +00:00
Dockerfile Fix the docker build image issue 2015-05-18 11:11:25 +08:00
HACKING.rst Remove unused hacking rule from HACKING.rst 2016-01-29 14:35:51 +08:00
LICENSE Initial commit from github (squashed) 2014-11-18 09:23:37 -05:00
MANIFEST.in Copy Ironic's database model codebase 2014-12-02 15:04:31 -07:00
README.rst Fix the representation of REST 2015-09-01 08:40:39 +05:30
babel.cfg Initial commit from github (squashed) 2014-11-18 09:23:37 -05:00
functional_creds.conf.sample Rename flavor name used in gate tests 2016-03-12 11:18:59 +05:30
requirements.txt Updated from global requirements 2016-07-14 09:19:48 +00:00
setup.cfg register the config generator default hook with the right name 2016-03-11 15:29:09 -05:00
setup.py Updated from global requirements 2015-09-17 12:12:49 +00:00
test-requirements.txt Updated from global requirements 2016-04-29 23:26:04 +00:00
tox.ini Remove bandit.yaml in favor of defaults 2016-03-09 11:20:28 -08:00

README.rst

Magnum

Magnum is an OpenStack project which offers container orchestration engines for deploying and managing containers as first class resources in OpenStack.

For more information, please refer to the following resources: