Bug 1020912 - Puppet modules fail to deploy on a node due to selinux
Summary: Puppet modules fail to deploy on a node due to selinux
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: SELinux
Version: 6.0.2
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: Unspecified
Assignee: Lukas Zapletal
QA Contact: Corey Welton
URL: http://projects.theforeman.org/issues...
Whiteboard:
Depends On:
Blocks: 1110814
TreeView+ depends on / blocked
 
Reported: 2013-10-18 13:54 UTC by Justin Sherrill
Modified: 2019-09-25 20:46 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 1110814 (view as bug list)
Environment:
Last Closed: 2014-09-11 12:28:00 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 6360 0 None None None 2016-04-22 16:37:19 UTC

Description Justin Sherrill 2013-10-18 13:54:42 UTC
Description of problem:

When syncing puppet repos to a node, puppet repositories will fail to publish properly to /etc/puppet/environments.  The following error will be seen in /var/log/pulp/pulp.log:


2013-10-17 16:06:53,905 pulp.server.managers.repo.publish:INFO: publish failed for repo [Katello_Infrastructure-Dev_Env-PublishedRHEL6Composite64-Puppet_Labs_Forge-Forge] with distributor ID [Katello_Infrastructure-Dev_Env-PublishedRHEL6Composite64-Puppet_Labs_Forge-Forge]




How reproducible:
Always

Steps to Reproduce:
1.  Deploy a node and ensure selinux is enabled
2.  Associate the node to an environment with a content view that contains a puppet repo
3.  Sync the node

Actual results:
Error (see above)


Expected results:
On the node /etc/puppet/environments/  should be populated with the puppet repo from the content view


Additional info:

For me, running restorecon did not seem to fix the problem

Comment 2 Ivan Necas 2013-10-21 06:41:30 UTC
I would move this to MDP3, as there is already known bug on puppetmaster deployment not working on selinux for now, see https://bugzilla.redhat.com/show_bug.cgi?id=1009964

Comment 4 Lukas Zapletal 2014-06-18 06:06:49 UTC
Justin,

it's because /etc/puppet is under puppet_etc_t context and not etc_t.

This needs to be fixed in pulp-selinux package. Please add AVC denials if you can.

I dont see "Pulp" component, do we clone bugs into upstream project or what?

Comment 7 Lukas Zapletal 2014-06-19 13:14:39 UTC
Pulp team evaluates possibilities. Putting on hold.

Comment 8 Lukas Zapletal 2014-06-24 10:24:40 UTC
I am unable to reproduce on satellite6 node, pulp works fine with our selinux policy. Trying out with capsule w/ puppetmaster.

Comment 9 Lukas Zapletal 2014-06-24 14:39:06 UTC
While I am still working on capsule reproducer, it looks like passenger on capsule is running under httpd_t domain. Puppet policy in RHEL6 for puppetmaster is not perfect and for Foreman we carry some fixes in foreman-selinux.

But on capsule/proxy we can't install foreman-selinux (due to foreman dependency). We have selinux policy breakup and smart proxy policy implementation on our TODO list, but we can't do this for beta.

We will likely see errors on the puppetmaster side (passenger process, httpd_t selinux domain). There are two workarounds this:

1) permissive

2) put httpd into unconfimed mode

Comment 10 Lukas Zapletal 2014-06-24 15:28:40 UTC
Ready for testing:

https://github.com/pulp/pulp/pull/1020

Comment 11 Lukas Zapletal 2014-06-25 09:02:02 UTC
Rel eng: The fix consists of two patches:

1) One for pulp selinux policy: https://github.com/pulp/pulp/pull/1020

2) One for katello installer: https://github.com/Katello/puppet-pulp/pull/20

Comment 12 Lukas Zapletal 2014-06-25 13:18:22 UTC
All patches merged, ready for downstream.

Comment 13 Lukas Zapletal 2014-06-25 13:42:46 UTC
Oh there is the third patch required, I had to update katello-installer:

3) https://github.com/Katello/katello-installer/pull/77

So disregard number (2) and only apply (1) and (3). I hope it's clear, if not, ping me :-) Sorry about that.

Comment 17 Corey Welton 2014-06-30 14:08:45 UTC
Pushing to 6.0.4 for testing.

Comment 18 Corey Welton 2014-09-02 18:49:03 UTC
Verified in Satellite-6.0.4-RHEL-7-20140829.0

Comment 19 Bryan Kearney 2014-09-11 12:28:00 UTC
This was delivered with Satellite 6.0 which was released on 10 September 2014.


Note You need to log in before you can comment on or make changes to this bug.