Andrew Bogott has uploaded a new change for review. ( 
https://gerrit.wikimedia.org/r/369839 )

Change subject: vmbuilder: remove /etc/ssh/userkeys/*
......................................................................

vmbuilder: remove /etc/ssh/userkeys/*

We want a fresh start, no keys on a new build.
This should prevent keys from accidentally leaking
from the build machine onto the base image.

Change-Id: I0d31bfb41eb54af20e2115a280aa04c65b805185
---
M modules/labs_vmbuilder/files/postinst.sh
1 file changed, 1 insertion(+), 0 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/39/369839/1

diff --git a/modules/labs_vmbuilder/files/postinst.sh 
b/modules/labs_vmbuilder/files/postinst.sh
index e06ac66..ff4b5ed 100644
--- a/modules/labs_vmbuilder/files/postinst.sh
+++ b/modules/labs_vmbuilder/files/postinst.sh
@@ -31,6 +31,7 @@
   mv /etc/puppet/puppet.conf.install /etc/puppet/puppet.conf
   mv /etc/default/puppet.install /etc/default/puppet
   rm /etc/ssh/ssh_host*key*
+  rm -rf /etc/ssh/userkeys/*
   sed -i 's/\/dev\/sda/\/dev\/vda/' /etc/fstab
   sed -i '/^kernel/s/$/ console=ttyS0/' /boot/grub/menu.lst
   sed -i 's/console=hvc0/xencons=hvc0 console=hvc0/' /boot/grub/menu.lst

-- 
To view, visit https://gerrit.wikimedia.org/r/369839
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: I0d31bfb41eb54af20e2115a280aa04c65b805185
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Andrew Bogott <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to