Skip to content

Scripts to mitigate CVEs with host patching#7

Open
rjaduthie wants to merge 4 commits into
pog-85-mitigate-cvefrom
main
Open

Scripts to mitigate CVEs with host patching#7
rjaduthie wants to merge 4 commits into
pog-85-mitigate-cvefrom
main

Conversation

@rjaduthie
Copy link
Copy Markdown
Contributor

No description provided.

seanmcconkey and others added 3 commits March 23, 2026 10:32
* Enable backup of databases to object store
* Ensure daily & frequent backups are treated separately
* Improve top-level documentation links from README
@rjaduthie rjaduthie force-pushed the pog-85-mitigate-cve branch 3 times, most recently from 51de317 to 33b8121 Compare May 8, 2026 17:20
…otD servers (#4)

* feat(DAAC-853): start the terraform for deplyment of the cam-preprod XRootD server, move ansible down to the xrootd/ansible dir

* feat(DAAC-853): commit latest changes, created the common ansible roles dir and moved the update_system role

* feat(DAAC-853): latest changes to follow ska-src-uksrc-cluster-gitops/docs/xrootd-config.md steps

* feat(DAAC-853): latest opentofu changes

* feat(DAAC-853): gets the server running on port 1094 with LetsEncrypt

* feat(DAAC-853): override the default 'rocky' user with our own 'uksrc-xrootd'

* feat(DAAC-853): dnf automatic updates - reboot 'when-needed' at 2am

* feat(DAAC-853): move the manage_users role to common

* feat(DAAC-853): add admin users and small changes to vars

* feat(DAAC-853): latest minoir changes and README updates

* feat(DAAC-853): add an example server tfvars file

* feat(DAAC-853): add GitHub's terraform directory .gitignore

* feat(DAAC-853): latest doc changes, example files, an encrypted host_vars file and fixes after XRootD access testing.

* fix(DAAC-853): switch the cert copy script to a template and make the server name a variable

* fis(DAAC-853): missed required config uncommented

* feat(DAAC-853): add the firewall setup

* feat(DAAC-853): restict access to port 1094 to the set of addresses

* doc(DAAC-853): update the xrootd-example-host-vars.example file

* feat(DAAC-853): add local network access from the bastion to port 1094 on the server

* fix(DAAC-853): address review comment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants