openshift / origin-aggregated-logging

139 stars 231 forks source link

LOG-2776: Enable FIPS mode to deploy elasticsearch on a FIPS enabled c #2258

Closed shwetaap closed 1 year ago

shwetaap commented 1 year ago

Signed-off-by: Shweta Padubidri spadubid@redhat.com

Description

OpenJDK17 in RHEL 8.6 supports PKSC#12 keystore. Remove the explicit disablement of the FIPS mode in JAVA_OPTIONS, to test if Elasticsearch can be correctly deployed on a FIPS enabled cluster.

/cc @kabirbhartiRH /assign @jcantrill

Links

shwetaap commented 1 year ago

/hold Allow QE to test this change

shwetaap commented 1 year ago

/retest

shwetaap commented 1 year ago

/retest

kabirbhartiRH commented 1 year ago

@shwetaap We need to build ES image base on java-17-openjdk-17.0.3.0.7-3.el8_6.src.rpm and then run this test on FIPS cluster.

Repo URL: http://brew-task-repos.usersys.redhat.com/repos/scratch/fferrari/java-17-openjdk/17.0.3.0.7/3.el8_6/

Not sure whether this PR includes that change.

openshift-ci[bot] commented 1 year ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: shwetaap Once this PR has been reviewed and has the lgtm label, please ask for approval from jcantrill by writing /assign @jcantrill in a comment. For more information see:The Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/openshift/origin-aggregated-logging/blob/master/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
kabirbhartiRH commented 1 year ago

/hold

jcantrill commented 1 year ago

/retest

openshift-ci[bot] commented 1 year ago

@shwetaap: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/cluster-logging-operator-e2e-5-3 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test cluster-logging-operator-e2e-5-3
ci/prow/elastic-operator-e2e-5-2 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link false /test elastic-operator-e2e-5-2
ci/prow/elastic-operator-e2e-5-3 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test elastic-operator-e2e-5-3
ci/prow/smoke-5-3 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test smoke-5-3
ci/prow/elastic-operator-e2e-5-6 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test elastic-operator-e2e-5-6
ci/prow/smoke-5-5 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test smoke-5-5
ci/prow/cluster-logging-operator-e2e-5-4 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test cluster-logging-operator-e2e-5-4
ci/prow/cluster-logging-operator-e2e-5-6 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test cluster-logging-operator-e2e-5-6
ci/prow/elastic-operator-e2e-5-4 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test elastic-operator-e2e-5-4
ci/prow/images ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test images
ci/prow/cluster-logging-operator-e2e-5-2 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link false /test cluster-logging-operator-e2e-5-2
ci/prow/smoke-5-4 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test smoke-5-4
ci/prow/cluster-logging-operator-e2e-5-5 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test cluster-logging-operator-e2e-5-5
ci/prow/smoke-5-6 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test smoke-5-6
ci/prow/elastic-operator-e2e-5-5 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link true /test elastic-operator-e2e-5-5
ci/prow/smoke-5-2 ae1d9608452b74107a3f3cd6368f590b21c6d4c5 link false /test smoke-5-2

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes/test-infra](https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
kabirbhartiRH commented 1 year ago

Hey @shwetaap, Are we looking to update the p12 keystore password for ES bootstrap scripts?

openshift-bot commented 1 year ago

Issues go stale after 90d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close. Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle stale