prashanthr2 commented on PR #662: URL: https://github.com/apache/cloudstack-documentation/pull/662#issuecomment-6015640199
+1 to @andrijapanicsb's points. A few things from the diff that I don't think are covered above: 1. On existing hosts, aa-enforce alone won't stick. Extending point 4 above, the old cloudstack-setup-agent didn't only unload the libvirt profiles, it symlinked them into /etc/apparmor.d/disable/. Those symlinks survive, so the profiles get skipped again at the next boot even after aa-enforce. The section needs a removal step first: _$ rm -f /etc/apparmor.d/disable/usr.sbin.libvirtd $ rm -f /etc/apparmor.d/disable/usr.lib.libvirt.virt-aa-helper_ 2. SUSE has been moved into a section with Debian-only commands. Dropping SUSE from the SELinux title and adding it to AppArmor is the right call, but the section still uses dpkg --list 'apparmor' and apt install apparmor-utils. SUSE needs zypper equivalents, or the step needs splitting per distro. 3. The same stale note is in _database.rst. The PR changes the body there to setenforce enforcing but leaves the .. note:: saying "in a production environment, selinux should be set to enforcing…" with the body now saying enforcing, the note just repeats it. Same note in kvm.rst. Both came from the "disable it" era and should be reworded along with the intro paragraph in point 5 above. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
