Bug 732442 - Reserve static uid/gids for OpenStack packages - swift, glance and nova
Reserve static uid/gids for OpenStack packages - swift, glance and nova
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: setup (Show other bugs)
rawhide
Unspecified Unspecified
low Severity low
: ---
: ---
Assigned To: Ondrej Vasik
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2011-08-22 09:36 EDT by Mark McLoughlin
Modified: 2011-08-23 05:32 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-08-23 04:25:14 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Mark McLoughlin 2011-08-22 09:36:29 EDT
As per:

  http://fedoraproject.org/wiki/Packaging:UsersAndGroups

The openstack-{swift,glance,nova} packages dynamically allocate uids and gids for the users they create

We'd prefer to have these uids and gids statically allocated in the uidgid file so that:

  1) The uids and gids are predictable

  2) We can shut up rpmlint's non-standard-uid warning

See bug #707199 and bug #731966

In summary, please allocate static uids and gids for the swift, glance and nova users
Comment 1 Ondrej Vasik 2011-08-22 09:53:00 EDT
Thanks for filing the request.
There are not only pros of static allocation... we have only 200 uidgid pairs which could be reserved statically - and more than 100 is already reserved - so static uidgid allocation should be used only if the system user account handles/stores sensitive data or if it is network facing/communicating between virtual machines - so predictable uid/gid makes sense there.

Is that your case? If so, could you please provide homedir and package which will create them for all these 3 users? I'll let you know which pairs will be reserved.
Comment 2 Mark McLoughlin 2011-08-22 10:23:33 EDT
Thanks Ondrej

All three accounts are used for network facing daemons which store sensitive data

Homedir for each is /var/lib/{swift,glance,nova} and packages are openstack-{swift,glance,nova}
Comment 3 Ondrej Vasik 2011-08-23 04:25:14 EDT
* Tue Aug 23 2011 Ondrej Vasik <ovasik@redhat.com> 2.8.38-1
- reserve 160:160 for swift (openstack-swift) - #732442
- reserve 161:161 for glance (openstack-glance) - #737442
- reserve 162:162 for nova (openstack-nova) - #737442

Closing RAWHIDE.
Comment 4 Ondrej Vasik 2011-08-23 04:26:04 EDT
oops, now I see typos in the changelog :) ... anyway, reserved uidgids are correct :)
Comment 5 Mark McLoughlin 2011-08-23 05:32:07 EDT
Thanks again Ondrej :)

Note You need to log in before you can comment on or make changes to this bug.