Accepting request 928144 from server:monitoring
OBS-URL: https://build.opensuse.org/request/show/928144 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/loki?expand=0&rev=5
This commit is contained in:
commit
c6bf95facb
23
harden_promtail.service.patch
Normal file
23
harden_promtail.service.patch
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
Index: loki-2.2.1+git.1617669398.babea82e/docs/sources/clients/aws/ec2/promtail.service
|
||||||
|
===================================================================
|
||||||
|
--- loki-2.2.1+git.1617669398.babea82e.orig/docs/sources/clients/aws/ec2/promtail.service
|
||||||
|
+++ loki-2.2.1+git.1617669398.babea82e/docs/sources/clients/aws/ec2/promtail.service
|
||||||
|
@@ -1,6 +1,18 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Promtail
|
||||||
|
[Service]
|
||||||
|
+# added automatically, for details please see
|
||||||
|
+# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort
|
||||||
|
+ProtectSystem=full
|
||||||
|
+ProtectHome=true
|
||||||
|
+PrivateDevices=true
|
||||||
|
+ProtectHostname=true
|
||||||
|
+ProtectClock=true
|
||||||
|
+ProtectKernelTunables=true
|
||||||
|
+ProtectKernelModules=true
|
||||||
|
+ProtectControlGroups=true
|
||||||
|
+RestrictRealtime=true
|
||||||
|
+# end of automatic additions
|
||||||
|
User=root
|
||||||
|
WorkingDirectory=/opt/promtail/
|
||||||
|
ExecStartPre=/bin/sleep 30
|
@ -1,3 +1,12 @@
|
|||||||
|
-------------------------------------------------------------------
|
||||||
|
Wed Oct 6 06:11:13 UTC 2021 - Johannes Segitz <jsegitz@suse.com>
|
||||||
|
|
||||||
|
- Added hardening to systemd service(s) (bsc#1181400). Added patch(es):
|
||||||
|
* harden_promtail.service.patch
|
||||||
|
Modified:
|
||||||
|
* loki.service
|
||||||
|
* promtail.service
|
||||||
|
|
||||||
-------------------------------------------------------------------
|
-------------------------------------------------------------------
|
||||||
Fri Jun 25 08:58:58 UTC 2021 - Stefano Torresi <stefano.torresi@suse.com>
|
Fri Jun 25 08:58:58 UTC 2021 - Stefano Torresi <stefano.torresi@suse.com>
|
||||||
|
|
||||||
|
12
loki.service
12
loki.service
@ -3,6 +3,18 @@ Description=Loki is a horizontally-scalable, highly-available, multi-tenant log
|
|||||||
Documentation=https://github.com/grafana/loki
|
Documentation=https://github.com/grafana/loki
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
|
# added automatically, for details please see
|
||||||
|
# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort
|
||||||
|
ProtectSystem=full
|
||||||
|
ProtectHome=true
|
||||||
|
PrivateDevices=true
|
||||||
|
ProtectHostname=true
|
||||||
|
ProtectClock=true
|
||||||
|
ProtectKernelTunables=true
|
||||||
|
ProtectKernelModules=true
|
||||||
|
ProtectControlGroups=true
|
||||||
|
RestrictRealtime=true
|
||||||
|
# end of automatic additions
|
||||||
Restart=always
|
Restart=always
|
||||||
User=loki
|
User=loki
|
||||||
EnvironmentFile=-/etc/sysconfig/loki
|
EnvironmentFile=-/etc/sysconfig/loki
|
||||||
|
@ -28,6 +28,7 @@ Source1: loki.service
|
|||||||
Source2: promtail.service
|
Source2: promtail.service
|
||||||
Source3: sysconfig.loki
|
Source3: sysconfig.loki
|
||||||
Source4: sysconfig.promtail
|
Source4: sysconfig.promtail
|
||||||
|
Patch0: harden_promtail.service.patch
|
||||||
BuildRoot: %{_tmppath}/%{name}-%{version}-build
|
BuildRoot: %{_tmppath}/%{name}-%{version}-build
|
||||||
BuildRequires: golang-packaging
|
BuildRequires: golang-packaging
|
||||||
BuildRequires: systemd-devel
|
BuildRequires: systemd-devel
|
||||||
@ -57,6 +58,7 @@ This package contains the Promtail client.
|
|||||||
|
|
||||||
%prep
|
%prep
|
||||||
%setup -q %{name}-%{version}
|
%setup -q %{name}-%{version}
|
||||||
|
%patch0 -p1
|
||||||
|
|
||||||
%build
|
%build
|
||||||
%define buildpkg github.com/grafana/loki/pkg/build
|
%define buildpkg github.com/grafana/loki/pkg/build
|
||||||
|
@ -3,6 +3,18 @@ Description=promtail is the agent responsible for gathering logs and sending the
|
|||||||
Documentation=https://github.com/grafana/loki/blob/master/docs/promtail.md
|
Documentation=https://github.com/grafana/loki/blob/master/docs/promtail.md
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
|
# added automatically, for details please see
|
||||||
|
# https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort
|
||||||
|
ProtectSystem=full
|
||||||
|
ProtectHome=true
|
||||||
|
PrivateDevices=true
|
||||||
|
ProtectHostname=true
|
||||||
|
ProtectClock=true
|
||||||
|
ProtectKernelTunables=true
|
||||||
|
ProtectKernelModules=true
|
||||||
|
ProtectControlGroups=true
|
||||||
|
RestrictRealtime=true
|
||||||
|
# end of automatic additions
|
||||||
Restart=always
|
Restart=always
|
||||||
User=loki
|
User=loki
|
||||||
EnvironmentFile=-/etc/sysconfig/promtail
|
EnvironmentFile=-/etc/sysconfig/promtail
|
||||||
|
Loading…
x
Reference in New Issue
Block a user