*** tkelsey has joined #openstack-security | 00:28 | |
*** tkelsey has quit IRC | 00:32 | |
*** markvoelker has quit IRC | 00:37 | |
*** bknudson has joined #openstack-security | 00:51 | |
*** edmondsw has quit IRC | 01:01 | |
*** markvoelker has joined #openstack-security | 01:17 | |
*** markvoelker has quit IRC | 01:22 | |
*** ukbelch has joined #openstack-security | 01:28 | |
*** ukbelch has quit IRC | 01:32 | |
*** bpokorny_ has quit IRC | 01:33 | |
*** browne has quit IRC | 01:48 | |
*** markvoelker has joined #openstack-security | 02:18 | |
*** browne has joined #openstack-security | 02:21 | |
*** markvoelker has quit IRC | 02:22 | |
*** jamielennox is now known as jamielennox|lunc | 02:32 | |
*** jamielennox|lunc is now known as jamielennox|food | 02:32 | |
*** tmcpeak has quit IRC | 02:36 | |
*** jamielennox|food is now known as jamielennox | 03:01 | |
*** subscope_ has joined #openstack-security | 03:05 | |
*** ukbelch has joined #openstack-security | 03:17 | |
*** markvoelker has joined #openstack-security | 03:19 | |
*** ukbelch has quit IRC | 03:21 | |
*** markvoelker has quit IRC | 03:23 | |
*** markvoelker has joined #openstack-security | 04:19 | |
*** markvoelker has quit IRC | 04:24 | |
*** tkelsey has joined #openstack-security | 04:36 | |
*** tkelsey has quit IRC | 04:41 | |
*** dave-mcc_ has joined #openstack-security | 04:57 | |
*** dave-mccowan has quit IRC | 04:57 | |
*** ukbelch has joined #openstack-security | 05:06 | |
*** ukbelch has quit IRC | 05:10 | |
*** markvoelker has joined #openstack-security | 05:20 | |
*** markvoelker has quit IRC | 05:25 | |
*** dave-mcc_ has quit IRC | 05:30 | |
*** markvoelker has joined #openstack-security | 06:21 | |
*** markvoelker has quit IRC | 06:26 | |
*** jamielennox is now known as jamielennox|away | 06:35 | |
*** subscope_ has quit IRC | 06:42 | |
*** ukbelch has joined #openstack-security | 06:52 | |
*** ukbelch has quit IRC | 06:56 | |
*** browne has quit IRC | 07:03 | |
*** markvoelker has joined #openstack-security | 07:22 | |
*** markvoelker has quit IRC | 07:27 | |
*** openstackgerrit has quit IRC | 08:22 | |
*** openstackgerrit has joined #openstack-security | 08:22 | |
*** markvoelker has joined #openstack-security | 08:22 | |
*** markvoelker has quit IRC | 08:27 | |
*** ukbelch has joined #openstack-security | 08:41 | |
*** ukbelch has quit IRC | 08:46 | |
*** ukbelch has joined #openstack-security | 09:02 | |
*** jamielennox|away is now known as jamielennox | 09:14 | |
*** tkelsey has joined #openstack-security | 09:19 | |
*** markvoelker has joined #openstack-security | 09:23 | |
*** tkelsey has quit IRC | 09:24 | |
*** ukbelch has quit IRC | 09:24 | |
*** tkelsey has joined #openstack-security | 09:24 | |
*** markvoelker has quit IRC | 09:28 | |
*** markvoelker has joined #openstack-security | 10:24 | |
*** markvoelker has quit IRC | 10:29 | |
*** tkelsey has quit IRC | 10:56 | |
*** tkelsey has joined #openstack-security | 10:56 | |
*** ukbelch has joined #openstack-security | 10:58 | |
*** tmcpeak has joined #openstack-security | 11:01 | |
*** ukbelch has quit IRC | 11:08 | |
*** ukbelch has joined #openstack-security | 11:44 | |
*** ukbelch has quit IRC | 11:51 | |
*** ukbelch has joined #openstack-security | 11:56 | |
*** markvoelker has joined #openstack-security | 12:03 | |
*** ukbelch has quit IRC | 12:16 | |
*** ukbelch has joined #openstack-security | 12:26 | |
*** bknudson has quit IRC | 12:29 | |
*** edmondsw has joined #openstack-security | 12:39 | |
*** singlethink has joined #openstack-security | 12:52 | |
*** bknudson has joined #openstack-security | 12:54 | |
*** jamielennox is now known as jamielennox|away | 13:36 | |
*** ljfisher has joined #openstack-security | 13:38 | |
*** tkelsey has quit IRC | 13:51 | |
*** raginbajin has joined #openstack-security | 13:55 | |
*** ukbelch has quit IRC | 13:56 | |
*** sicarie has joined #openstack-security | 14:09 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Adding new introudctions for chapters missing one https://review.openstack.org/164883 | 14:23 |
---|---|---|
*** singlethink has quit IRC | 14:36 | |
*** dave-mccowan has joined #openstack-security | 14:41 | |
*** singlethink has joined #openstack-security | 14:41 | |
*** voodookid has joined #openstack-security | 14:43 | |
*** voodookid has quit IRC | 14:47 | |
*** browne has joined #openstack-security | 14:50 | |
*** elo has joined #openstack-security | 14:57 | |
*** voodookid has joined #openstack-security | 15:02 | |
*** dwyde has joined #openstack-security | 15:02 | |
*** bpokorny has joined #openstack-security | 15:18 | |
*** openstackgerrit has quit IRC | 15:21 | |
*** openstackgerrit has joined #openstack-security | 15:22 | |
*** ukbelch has joined #openstack-security | 15:22 | |
*** singlethink has quit IRC | 15:30 | |
sicarie | Does anyone here know of decent SELinux/AppArmor profiles for OpenStack? | 15:43 |
sicarie | I found https://github.com/openstack/tripleo-image-elements/tree/master/elements/selinux | 15:43 |
sicarie | But was curious if anyone knew if more was out there | 15:43 |
nkinder | sicarie: there is quite a bit of openstack stuff in the base selinux-policy on RHEL/CentOS/Fedora | 15:44 |
sicarie | awesome, thanks nkinder | 15:45 |
nkinder | Also, there is an openstack-selinux package that has additional policy that layers on-top | 15:45 |
sicarie | Interesting, I was not aware of that | 15:45 |
nkinder | I don't really see people writing additional policy on a per-deployment basis (maybe labelling some custom paths or things like that) | 15:45 |
sicarie | Yeah, I'm trying to put together some stuff for the secgude on the compute section | 15:46 |
sicarie | The Philly notes were really interesting | 15:46 |
*** browne has quit IRC | 15:46 | |
nkinder | the ops meeting? | 15:46 |
sicarie | yeah | 15:46 |
*** dwyde has quit IRC | 15:47 | |
sicarie | I don't remember if it was in there, or in a bug linked from there, but they were talking about pushing the responsibility for the selinux/apparmor profiles to the individual operators | 15:47 |
nkinder | yeah, some interesting stuff | 15:47 |
*** elo has quit IRC | 15:47 | |
nkinder | wow, that seems like a lot to ask of an operator | 15:47 |
nkinder | writing policy can be pretty tough | 15:47 |
*** dwyde has joined #openstack-security | 15:47 | |
sicarie | I was surprised by that statement as well | 15:47 |
*** singlethink has joined #openstack-security | 16:15 | |
openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 16:19 |
*** ukbelch has quit IRC | 16:26 | |
sicarie | Comments/critiques welcome on my current outline for Compute chapter: https://bugs.launchpad.net/openstack-manuals/+bug/1412975 | 16:31 |
openstack | Launchpad bug 1412975 in openstack-manuals "Security Guide - Compute Section" [Low,Confirmed] - Assigned to N Dillon (sicarie) | 16:31 |
sicarie | nkinder: I didn't include rdo/rhel selinux policies in there as I couldn't see them in a public repo, digging into rdo's is on my todo list | 16:31 |
sicarie | This is just my cursory pass, I have more to do on each section | 16:32 |
*** browne has joined #openstack-security | 16:35 | |
*** ljfisher has quit IRC | 16:37 | |
nkinder | sicarie: it's all public | 16:41 |
sicarie | nkinder: what I saw on the rdo site (and again, this is with ~10seconds of Googl'ing) linked to an empty git repo | 16:42 |
nkinder | sicarie: SRPM is the best way to get at it | 16:42 |
tmcpeak | if it doesn't exist in 10 seconds of googling, it doesn't exist ;) | 16:42 |
sicarie | So what I found right away was: https://github.com/redhat-openstack/openstack-selinux | 16:43 |
nkinder | sicarie: ftp://ftp.redhat.com/redhat/linux/enterprise/7Server/en/RHOS/SRPMS/ | 16:44 |
sicarie | integrated into rdo definitely deserves a mention, but I want to be able to call out what does and doesn't hav epolicies | 16:44 |
sicarie | Awesome | 16:44 |
nkinder | that will have the openstack-selinux SRPMS for RHEL OSP | 16:44 |
nkinder | sicarie: RHEL SRPMS are now hosted via centos | 16:45 |
nkinder | https://git.centos.org/project/rpms | 16:45 |
sicarie | nkinder: thanks, did not know about this yet! | 16:46 |
*** openstackgerrit has quit IRC | 17:21 | |
*** openstackgerrit has joined #openstack-security | 17:21 | |
*** ljfisher has joined #openstack-security | 17:27 | |
openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 17:28 |
*** ukbelch has joined #openstack-security | 17:33 | |
openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 17:34 |
*** ukbelch has quit IRC | 17:39 | |
*** rkgudboy has joined #openstack-security | 17:43 | |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Moving introduction sections 'up' from section_* files to ch_* files https://review.openstack.org/164526 | 17:45 |
*** rkgudboy has quit IRC | 17:50 | |
*** dwyde has quit IRC | 17:53 | |
*** bpokorny_ has joined #openstack-security | 17:56 | |
*** bpokorn__ has joined #openstack-security | 17:58 | |
*** bpokorny has quit IRC | 17:59 | |
*** bpokorny has joined #openstack-security | 18:00 | |
*** bpokorny_ has quit IRC | 18:02 | |
*** JAHoagie has joined #openstack-security | 18:02 | |
*** bpokorn__ has quit IRC | 18:04 | |
tmcpeak | nkinder: you around? | 18:04 |
nkinder | tmcpeak: yep | 18:06 |
tmcpeak | no judgies: http://pastebin.com/bAGv7RBU | 18:06 |
tmcpeak | super hack city | 18:06 |
tmcpeak | but it works | 18:06 |
tmcpeak | open question - how to handle newlines | 18:06 |
nkinder | tmcpeak: well, we're going to need a program to do the inverse conversion (YAML -> e-mail format) | 18:07 |
tmcpeak | That should be easy | 18:07 |
nkinder | I think that's where we will have logic to put newlines at the correct wrapping width | 18:08 |
tmcpeak | sure, yeah that's no problem | 18:08 |
nkinder | So in YAML, I'm not too picky about where the newlines would be | 18:08 |
tmcpeak | the difficult part with this is, sometimes we obviously want to preserve newlines, like around code segments | 18:08 |
nkinder | Yes, so maybe we have no newlines except those that we want to preserve | 18:08 |
nkinder | ...in YAML | 18:08 |
nkinder | then we wrap long lines in the YAML->OSSN automagically | 18:09 |
tmcpeak | yeah, but how do you programatically determine which newlines you want to preserve? | 18:09 |
nkinder | well that's the rub :) | 18:09 |
tmcpeak | yeah, prob not possible | 18:09 |
nkinder | I don't think we can | 18:09 |
tmcpeak | yeah, so I think this is as close to magic we can do for this | 18:09 |
tmcpeak | has dropped text into yaml format sensibly | 18:09 |
tmcpeak | now we just need to clean up | 18:09 |
tmcpeak | shouldn't be too much labor | 18:09 |
nkinder | yeah, just a bit of mindless manual work :) | 18:10 |
tmcpeak | yep yep | 18:11 |
tmcpeak | so.. my weekend tribute to you nkinder is that hacky script :P | 18:11 |
nkinder | thanks! | 18:11 |
tmcpeak | sure thing | 18:11 |
tmcpeak | nkinder: when we're ready for other way around I can bang something up that will wrap lines back | 18:12 |
*** dwyde has joined #openstack-security | 18:14 | |
*** dwyde has quit IRC | 18:15 | |
openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 18:21 |
*** ukbelch has joined #openstack-security | 18:21 | |
*** tkelsey has joined #openstack-security | 18:21 | |
*** ukbelch has quit IRC | 18:35 | |
*** sweston has quit IRC | 18:38 | |
*** erw has quit IRC | 18:39 | |
*** dwyde has joined #openstack-security | 18:49 | |
*** ukbelch has joined #openstack-security | 19:02 | |
*** tkelsey has quit IRC | 19:03 | |
*** dwyde has quit IRC | 19:07 | |
*** ukbelch has quit IRC | 19:26 | |
*** jeanmanuel has joined #openstack-security | 19:54 | |
*** singlethink has quit IRC | 19:55 | |
jeanmanuel | hola | 19:55 |
jeanmanuel | quien habla espaƱol | 19:55 |
*** jeanmanuel has left #openstack-security | 19:55 | |
*** jeanmanuel has joined #openstack-security | 19:56 | |
*** jeanmanuel has left #openstack-security | 19:56 | |
*** singlethink has joined #openstack-security | 20:05 | |
*** erw has joined #openstack-security | 20:15 | |
*** sweston has joined #openstack-security | 20:16 | |
openstackgerrit | Shellee Arnold proposed openstack/security-doc: Fix for restatement of duplicated work https://review.openstack.org/163946 | 20:35 |
*** hyakuhei has joined #openstack-security | 20:46 | |
*** ljfisher has quit IRC | 20:57 | |
*** tkelsey has joined #openstack-security | 21:00 | |
*** tkelsey has quit IRC | 21:04 | |
*** bpokorny_ has joined #openstack-security | 21:09 | |
*** sicarie has quit IRC | 21:12 | |
*** bpokorny has quit IRC | 21:13 | |
*** hyakuhei has quit IRC | 21:24 | |
*** singlethink has quit IRC | 21:36 | |
*** jamielennox|away is now known as jamielennox | 21:49 | |
*** singlethink has joined #openstack-security | 21:52 | |
*** edmondsw has quit IRC | 21:53 | |
*** JAHoagie has quit IRC | 22:03 | |
*** jamielennox is now known as jamielennox|away | 22:05 | |
*** JAHoagie has joined #openstack-security | 22:31 | |
*** singlethink has quit IRC | 22:34 | |
*** bknudson has quit IRC | 22:36 | |
*** JAHoagie has quit IRC | 22:47 | |
*** voodookid has quit IRC | 22:49 | |
*** dave-mccowan has quit IRC | 23:20 | |
*** tkelsey has joined #openstack-security | 23:31 | |
*** tkelsey has quit IRC | 23:35 | |
*** dave-mccowan has joined #openstack-security | 23:38 | |
*** markvoelker has quit IRC | 23:42 | |
*** JAHoagie has joined #openstack-security | 23:50 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!