Bug 845078 - Reserve static UID/GID for OpenStack heat daemon
Reserve static UID/GID for OpenStack heat daemon
Product: Fedora
Classification: Fedora
Component: setup (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Ondrej Vasik
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2012-08-01 12:51 EDT by Steven Dake
Modified: 2016-04-26 22:19 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-08-06 07:23:40 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Steven Dake 2012-08-01 12:51:27 EDT
Description of problem:
As per:


The heat package requires a static UID/GID combination for security concerns.  We would rather not dynamically allocate this UID/GID as it could cause problems during upgrade or backup and we wish to quiet rpmlint.
Version-Release number of selected component (if applicable):
Rawhide - targeted at F18

Additional info:
Heat is a network facing daemon which contains sensitive user information in its persistent storage area.  The persistent storage area is /var/lib/heat.  The current packaging uses root permissions.  We absolutely don't want heat to run as root user, so our alternative is a dynamic UID/GID which would result in problems during the upgrade or backup process.

The uid/gid combo desired is 'openstack-heat'.

Comment 1 Ondrej Vasik 2012-08-05 15:33:04 EDT
Just to be sure - so the reserved user/group name should be openstack-heat and homedir should be /var/lib/heat? Which package will be responsible for the user/group creation? Shell should be /sbin/nologin , right?
Comment 2 Steven Dake 2012-08-05 17:56:15 EDT
yes user/group are openstack-heat, homedir should be /var/lib/heat.  Shell should be /sbin/nologin.  The package responsible for creation can either be setup or heat, depending on what you think is appropriate.

Comment 3 Ondrej Vasik 2012-08-06 07:23:40 EDT
heat package is more appropriate for the user/group creation. I have reserved 187:187 uidgid pair for openstack-heat in setup-2.8.57-1.fc18 , feel free to use this static id in your next heat build. Closing RAWHIDE.
Comment 4 Jeff Peeler 2013-05-28 18:30:37 EDT
Note that this was renamed to just "heat" in bug 923858.

Note You need to log in before you can comment on or make changes to this bug.