tiiuae / ghaf

TII SSRC Secure Technologies: Ghaf Framework
https://tiiuae.github.io/ghaf/
Apache License 2.0
35 stars 56 forks source link

logging: Update the logging server endpoint #700

Closed vunnyso closed 1 month ago

vunnyso commented 1 month ago

With updated server endpoint url, loki will be using https with basic auth. Access using insecure ip:port and http no longer possible.

Description of changes

Checklist for things done

Testing

Prerequisite: Depends on https://github.com/tiiuae/ghaf-infra/pull/207 to deployed on server (Now its Merged and Deployed).

What can be checked? Need to identify if there is more frequent journal logs from system with this change and check if any other issues found.

vunnyso commented 1 month ago

ghaf-infra change already merged https://github.com/tiiuae/ghaf-infra/pull/207

brianmcgillion commented 1 month ago

image

brianmcgillion commented 1 month ago

the gap shows that the messages stopped when the new server hardening was deployed and now it is active again after these changes are applied to the device image

brianmcgillion commented 1 month ago

image

brianmcgillion commented 1 month ago

it seems that there is a lot more traffic being created in the net-vmafter the change. the left side of the image was the status with pr #701. the break is when the server hardening was deployed. the right side is with this #700 applied and starting to log.

vunnyso commented 1 month ago

it seems that there is a lot more traffic being created in the net-vmafter the change. the left side of the image was the status with pr #701. the break is when the server hardening was deployed. the right side is with this #700 applied and starting to log.

I have tried on my setup I have noticed only minor spikes in net-vm with #700 change.

image

leivos-unikie commented 1 month ago

Test results:

Regarding traffic caused by logging I tried iftop -t -s 300 > iftop.txt in admin-vm: iftop.txt

In addition: