[OpenStack-Infra] Removal of infra-root shell accounts from nodepool DIBs

Jeremy Stanley fungi at yuggoth.org
Wed Apr 19 23:42:30 UTC 2017


On 2017-04-19 17:49:13 -0400 (-0400), Paul Belanger wrote:
[...]
> We'll now be using ansible-role-cloud-launcher[2] to populate the
> infra-root-keys keypair for all our clouds. This means that glean will then
> inject our keypairs into the authorized_keys file for the root user.
> 
> One step closer to dropping puppet from our image build process.

Also, this brings the images we're using much closer to potential
reusability outside our CI system since people no longer need to
doctor them to remove our default admin access.
-- 
Jeremy Stanley



More information about the OpenStack-Infra mailing list