Project

General

Profile

Actions

action #157555

open

openQA Project - coordination #105624: [saga][epic] Reconsider how openQA handles secrets

openQA Project - coordination #157537: [epic] Secure setup of openQA test machines with secure network+secure authentication

[spike][timeboxed:10h][qe-core] Use a different ssh root password for s390x kvm installation openQA jobs (or svirt) size:S

Added by okurz about 1 month ago. Updated 19 days ago.

Status:
Workable
Priority:
High
Assignee:
-
Category:
-
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Difficulty:

Description

Motivation

In https://sd.suse.com/servicedesk/customer/portal/1/SD-150437 we are asked to handle "compromised root passwords in QA segments" including s390zl11…16

Goals

  • G1: Have an s390x kvm openQA installation job with non-default password succeed as far as possible
  • G2: Identify which follow-up steps need to be done to fully support non-default passwords in such scenarios

Suggestions


Related issues 2 (1 open1 closed)

Copied to openQA Tests - action #157744: [spike][timeboxed:10h][qe-core] Use ssh key authentication in particular for s390x kvm installation openQA jobsWorkable2024-03-22

Actions
Copied to openQA Infrastructure - action #158242: Prevent ssh access to test VMs on svirt hypervisor hosts with firewall size:MRejecteddheidler2024-03-282024-04-20

Actions
Actions #1

Updated by okurz about 1 month ago

  • Copied to action #157744: [spike][timeboxed:10h][qe-core] Use ssh key authentication in particular for s390x kvm installation openQA jobs added
Actions #2

Updated by okurz about 1 month ago

  • Priority changed from Normal to High
  • Target version changed from future to Ready

According to https://sd.suse.com/servicedesk/customer/portal/1/SD-150437 we likely need this sooner rather than later. Adding to our backlog.

Actions #3

Updated by livdywan 30 days ago

  • Subject changed from [spike][timeboxed:10h] Use a different ssh root password for s390x kvm installation openQA jobs to [spike][timeboxed:10h] Use a different ssh root password for s390x kvm installation openQA jobs (or svirt) size:S
  • Description updated (diff)
  • Status changed from New to Workable
Actions #4

Updated by okurz 30 days ago

  • Assignee set to okurz

I have an alternative idea: firewall on svirt hosts preventing access from outside only workers in the same network OR openQA workers on the hypervisor hosts themselves

Actions #5

Updated by okurz 30 days ago

  • Copied to action #158242: Prevent ssh access to test VMs on svirt hypervisor hosts with firewall size:M added
Actions #6

Updated by okurz 30 days ago

  • Status changed from Workable to Blocked
  • Target version changed from Ready to Tools - Next

Created #158242, let's try that first.

Actions #7

Updated by okurz 19 days ago

  • Project changed from openQA Infrastructure to openQA Tests
  • Subject changed from [spike][timeboxed:10h] Use a different ssh root password for s390x kvm installation openQA jobs (or svirt) size:S to [spike][timeboxed:10h][qe-core] Use a different ssh root password for s390x kvm installation openQA jobs (or svirt) size:S
  • Category deleted (Feature requests)
  • Status changed from Blocked to Workable
  • Assignee deleted (okurz)
  • Target version changed from Tools - Next to QE-Core: Ready

@qe-core I have a new task for you that should be planned to work on within the next weeks/months so that we don't get escalations from SUSE's cybersecurity team. Related #157744

Actions

Also available in: Atom PDF