New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 773085 link

Starred by 2 users

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

sshd_config on lab devservers should be puppet-managed

Project Member Reported by akes...@chromium.org, Oct 9 2017

Issue description

Lack of puppet control contributed to Issue 771236 by making an attempt to roll an sshd_config change to devservers unexpectedly fail.

+phobbs can you comment on the current state of knowledge of why lab servers were different?
 
Cc: dgarr...@chromium.org
Lab servers are not Goobuntu, and our puppet configuration only manages the sshd config for Goobuntu machines. I'm not sure how we got into this state - why did we decide to special case Goobuntu devservers?
No idea, but I think we should control it.

And having read through both sshd configs, I believe the Goobuntu one should work on Ubuntu. However, it's better to test. 

Do we have a way to test puppet config changes on the staging lab servers?
#1 Probably we special cased lab devservers, since they are Ubuntu and probably were added later.

#2 Do we have a way to test puppet config changes on the staging lab servers?

Sort of.  Not that it matter in this case, since there are no lab devservers in the staging lab setup (I think).

Quick notes for things to check:

1. Ubuntu and Goobuntu use which versions of OpenSSH?
2. What are the default values for all of the Goobuntu settings that are missing from Ubuntu?
3. Are there any settings in the Ubuntu config that are not in the Goobuntu config?
3a. Do we merge those settings back?
3aa. What are the default values for those settings in the Goobuntu version of OpenSSH?
3b. Do we drop those settings?
3ba. What are the default values for those settings in the Ubuntu version of OpenSSH?

Alternatively, push it and see if anything breaks.  Much easier.
There is one staging devserver. I believe it's in the lab, though I don't know which machine it is.

Comment 6 by cindyb@chromium.org, May 31 2018

Hi, this bug has not been updated recently and remains untriaged. Please acknowledge the bug and provide status within two weeks (6/8/2018), or the bug will be closed. Thank you.
Components: -Infra>Client>ChromeOS Infra>Client>ChromeOS>Test
Status: Available (was: Untriaged)

Sign in to add a comment