From 3f607749c5791a0c6ff68b989aac8d989165085b Mon Sep 17 00:00:00 2001 From: Ilya Kharin Date: Thu, 29 Dec 2016 14:46:39 +0400 Subject: [PATCH 1/3] Fix security running commands --- docker-compose.yml | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 3399405..d1a9ca7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -24,7 +24,9 @@ services: volumes: - ${DIR}/configs/security:/etc/oss/security:ro entrypoint: - - security-checker --config-file /etc/oss/security/config.yaml + - security-checker + - --config-file + - /etc/oss/security/config.yaml networks: - oss-net restart: always @@ -55,8 +57,10 @@ services: image: seecloud/security:${TAG:-latest} volumes: - ${DIR}/configs/security:/etc/oss/security:ro + environment: + - SECURITY_CONF=/etc/oss/security/config.yaml entrypoint: - - security-api --config-file /etc/oss/security/config.yaml + - ./entrypoint-api.sh networks: - oss-net restart: always From ece51da18a1525fee4debc2258da0e0086431e68 Mon Sep 17 00:00:00 2001 From: Ilya Kharin Date: Thu, 5 Jan 2017 22:14:18 +0000 Subject: [PATCH 2/3] Use appropriate regions for security --- configs/security/config.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/configs/security/config.yaml b/configs/security/config.yaml index f6a3d18..af70510 100644 --- a/configs/security/config.yaml +++ b/configs/security/config.yaml @@ -1,6 +1,6 @@ regions: - type: openstack - name: lab1 + name: cz-1.lab credentials: auth_url: https://OPENSTACK_IP:5000/v2.0/ username: OPENSTACK_USERNAME @@ -11,7 +11,7 @@ plugins: - module: security.plugins.secgroup checkEveryMinutes: 1 regions: - - lab1 + - cz-1.lab elastic: hosts: From 754793ab7c6b20fe97cbe53fe82990784ccf3e5c Mon Sep 17 00:00:00 2001 From: Ilya Kharin Date: Thu, 5 Jan 2017 23:45:57 +0000 Subject: [PATCH 3/3] Add endpoint_override for security --- configs/security/config.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/configs/security/config.yaml b/configs/security/config.yaml index af70510..e05d9ef 100644 --- a/configs/security/config.yaml +++ b/configs/security/config.yaml @@ -6,6 +6,8 @@ regions: username: OPENSTACK_USERNAME password: OPENSTACK_PASSWORD tenant_name: OPENSTACK_TENANT_NAME + insecure: true + endpoint_override: https://OPENSTACK_IP:9696/ plugins: - module: security.plugins.secgroup