[Openstack-security] [Bug 1702123] Re: SELinux error: keepalived reading haproxy pid file

OpenStack Infra 1702123 at bugs.launchpad.net
Wed Aug 23 21:04:24 UTC 2017


Reviewed:  https://review.openstack.org/494612
Committed: https://git.openstack.org/cgit/openstack/openstack-ansible/commit/?id=25becb3c09e092001b0789b48d86ea53d20f73bb
Submitter: Jenkins
Branch:    stable/ocata

commit 25becb3c09e092001b0789b48d86ea53d20f73bb
Author: Major Hayden <major at mhtx.net>
Date:   Thu Aug 17 10:38:46 2017 -0500

    Allow Keepalived to read haproxy pid file
    
    This is a combined backport of the master patch to add a SELinux rule
    that allows keepalived to read haproxy's PID file. It also includes
    a bump of ansible-keepalived to 3.0.2.
    
    Closes-Bug: 1702123
    Change-Id: I3e206d0f2de663c9612d15444a827baf166af8d9


** Tags added: in-stable-ocata

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1702123

Title:
  SELinux error: keepalived reading haproxy pid file

Status in openstack-ansible:
  Fix Released

Bug description:
  When keepalived tries to read the haproxy PID file, SELinux denies the
  access. This should be added into the haproxy role.

To manage notifications about this bug go to:
https://bugs.launchpad.net/openstack-ansible/+bug/1702123/+subscriptions




More information about the Openstack-security mailing list