chaoss / grimoirelab-elk

GNU General Public License v3.0
60 stars 121 forks source link

Removal of the code that generates the "conf" index #221

Closed hmitsch closed 5 years ago

hmitsch commented 6 years ago

Desirement Source: https://github.com/mozilla/participation-metrics-org/issues/157

Short Description: A vulnerability assessment conducted by Mozilla's Enterprise Information Security team revealed, that

https://analytics.mozilla.community/elasticsearch/conf/_search leaks some configuration data eg: "git command - fatal: could not create leading directories of '/home/bitergia/.perceval/repositories/https://github.com/MozillaFoundation/Design.git-git'\n"

Potential Solution: According to @acs:

This data is not used anymore. Is legacy stuff that must be removed.

/cc @gdestuynder @sanacl

acs commented 6 years ago

@hmitsch once https://github.com/chaoss/grimoirelab-elk/pull/243 gets accepted the index won't be created anymore. And it is safe to remove it from the current deployments.

valeriocos commented 5 years ago

better late than never, closing this issue since fixed by #243