prashanthr2 commented on PR #662:
URL: 
https://github.com/apache/cloudstack-documentation/pull/662#issuecomment-6015640199

   +1 to @andrijapanicsb's points. A few things from the diff that I don't 
think are covered above:
   
   1. On existing hosts, aa-enforce alone won't stick. Extending point 4 above, 
the old cloudstack-setup-agent didn't only unload the libvirt profiles, it 
symlinked them into /etc/apparmor.d/disable/. Those symlinks survive, so the 
profiles get skipped again at the next boot even after aa-enforce. The section 
needs a removal step first:
   _$ rm -f /etc/apparmor.d/disable/usr.sbin.libvirtd
   $ rm -f /etc/apparmor.d/disable/usr.lib.libvirt.virt-aa-helper_
   
   2. SUSE has been moved into a section with Debian-only commands. Dropping 
SUSE from the SELinux title and adding it to AppArmor is the right call, but 
the section still uses dpkg --list 'apparmor' and apt install apparmor-utils. 
SUSE needs zypper equivalents, or the step needs splitting per distro.
   
   3. The same stale note is in _database.rst. The PR changes the body there to 
setenforce enforcing but leaves the .. note:: saying "in a production 
environment, selinux should be set to enforcing…"  with the body now saying 
enforcing, the note just repeats it. Same note in kvm.rst. Both came from the 
"disable it" era and should be reworded along with the intro paragraph in point 
5 above.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to