Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update warden stage to support Noble #397

Merged
merged 2 commits into from
Dec 5, 2024
Merged

Conversation

jpalermo
Copy link
Member

  • Enable systemd in the container
  • Remove all runit shims that were previously included because systemd was not being used
  • local_events must be disabled for auditd due to running in a container
  • systemd DefaultStartLimitBurst must be increased because some services are restarted more than 5 times in 5 seconds on agent startup (systemd-resolvd was seen at least)
  • Disable pam_faillock module. This was a differnet pam module in Jammy and prior. It's used to show number of previous failed login attempts. It seems that when it's enabled within a container sshd is unable to properly tracker users and causes ssh-ing into the container to fail.

- Enable systemd in the container
- Remove all runit shims that were previously included because systemd was not being used
- local_events must be disabled for auditd due to running in a container
- systemd DefaultStartLimitBurst must be increased because some services are restarted more than 5 times in 5 seconds on agent startup (systemd-resolvd was seen at least)

Signed-off-by: Joseph Palermo <[email protected]>
Co-authored-by: Joseph Palermo <[email protected]>
@jpalermo jpalermo force-pushed the pr-noble-warden-fixes branch from 3ca5ff7 to d4d86af Compare November 28, 2024 06:38
@rkoster rkoster requested review from ramonskie, a team and ystros and removed request for a team November 28, 2024 16:08
ystros
ystros previously approved these changes Dec 2, 2024
aramprice
aramprice previously approved these changes Dec 4, 2024
ramonskie
ramonskie previously approved these changes Dec 4, 2024
Copy link
Contributor

@ramonskie ramonskie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tested it and work

@beyhan beyhan dismissed stale reviews from ramonskie, aramprice, and ystros via c1d1c17 December 5, 2024 15:41
Copy link
Contributor

@ramonskie ramonskie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@beyhan beyhan merged commit 9075356 into ubuntu-noble Dec 5, 2024
1 check passed
@beyhan beyhan deleted the pr-noble-warden-fixes branch December 5, 2024 15:42
ramonskie added a commit that referenced this pull request Dec 12, 2024
jpalermo pushed a commit that referenced this pull request Dec 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

Successfully merging this pull request may close these issues.

6 participants