When provisioning a machine, the client needs to access foreman unattended urls, such as: http://foreman/unattended/kickstart and http://foreman/unattended/built That means firewall open to foreman (and the API). I think the architecture and security would improve if Foreman could be as isolated as possible, not depending on being open to the machines it manages... Those tasks should be left to the proxy. The suggested solution: Client communications directed to Foreman should me moved to proxy (in this case, the one running on the master) so you only need port 8140(puppetmaster) + 8443 (foreman-proxy) open. Note: The proxy doesn’t really need to simply forward the request (although this is also a valid initial solution). It could have some intelligence to validate them or serve the unattended itself (pre fetching template information or something like it)… http://i.imgur.com/aJlN5.png
Created from redmine issue http://projects.theforeman.org/issues/969
Upstream bug assigned to dtsang
qe -> kbidarka since he's been looking at the provisioning stuff. Assuming this can be verified...
When validating, be sure to run the capsule-installer with the options to enable the Templates feature in addition to TFTP: "--tftp=true --templates=true"
VERIFIED With capsule running on Satellite-6.1.0-RHEL-7-20150424.0
*** Bug 1218115 has been marked as a duplicate of this bug. ***
This bug is slated to be released with Satellite 6.1.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2015:1592