Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1197806 - [RFE] Direct Client->Foreman communication shouldn't be needed for provisioning templates
[RFE] Direct Client->Foreman communication shouldn't be needed for provisioni...
Status: CLOSED ERRATA
Product: Red Hat Satellite 6
Classification: Red Hat
Component: Capsule (Show other bugs)
6.0.4
Unspecified Unspecified
unspecified Severity high (vote)
: Unspecified
: Unused
Assigned To: Mike McCune
Kedar Bidarkar
http://projects.theforeman.org/issues...
: FutureFeature
: 1218115 (view as bug list)
Depends On:
Blocks: 1175803
  Show dependency treegraph
 
Reported: 2015-03-02 11:24 EST by Stephen Benjamin
Modified: 2017-02-23 15:24 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-12 01:28:19 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Foreman Issue Tracker 969 None None None 2016-04-22 12:15 EDT
Red Hat Product Errata RHSA-2015:1592 normal SHIPPED_LIVE Important: Red Hat Satellite 6.1.1 on RHEL 6 2015-08-12 05:04:35 EDT

  None (edit)
Description Stephen Benjamin 2015-03-02 11:24:07 EST
When provisioning a machine, the client needs to access foreman unattended urls, such as: 
http://foreman/unattended/kickstart
and
http://foreman/unattended/built

That means firewall open to foreman (and the API).
I think the architecture and security would improve if Foreman could be as isolated as possible, not depending on being open to the machines it manages... Those tasks should be left to the proxy.

The suggested solution:
Client communications directed to Foreman should me moved to proxy (in this case, the one running on the master) so you only need port 8140(puppetmaster) + 8443 (foreman-proxy) open.

Note:
The proxy doesn’t really need to simply forward the request (although this is also a valid initial solution). It could have some intelligence to validate them or serve the unattended itself (pre fetching template information or something like it)…

http://i.imgur.com/aJlN5.png
Comment 1 Stephen Benjamin 2015-03-02 11:24:09 EST
Created from redmine issue http://projects.theforeman.org/issues/969
Comment 5 Steve Loranz 2015-03-11 18:14:12 EDT
Upstream bug assigned to dtsang@redhat.com
Comment 6 Corey Welton 2015-03-24 22:18:51 EDT
qe -> kbidarka since he's been looking at the provisioning stuff.  Assuming this can be verified...
Comment 10 Stephen Benjamin 2015-04-30 11:28:40 EDT
When validating, be sure to run the capsule-installer with the options to enable the Templates feature in addition to TFTP:


"--tftp=true --templates=true"
Comment 12 Kedar Bidarkar 2015-05-07 12:49:21 EDT
VERIFIED With capsule running on Satellite-6.1.0-RHEL-7-20150424.0
Comment 13 Stephen Benjamin 2015-05-12 07:54:47 EDT
*** Bug 1218115 has been marked as a duplicate of this bug. ***
Comment 15 Bryan Kearney 2015-08-11 09:30:25 EDT
This bug is slated to be released with Satellite 6.1.
Comment 16 errata-xmlrpc 2015-08-12 01:28:19 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2015:1592

Note You need to log in before you can comment on or make changes to this bug.