Uploaded image for project: 'Logging analytics'
  1. Logging analytics
  2. LOG-481

ConfigMap is ReadOnly - The owner of elasticsearch.yml should be “elasticsearch” not root.

XMLWordPrintable

      Rancher ONAP OOM deployment do not deploy ONAP ElasticSearch properly. The owner of elasticsearch.yml  should be “elasticsearch” not root. We cannot modify elasticsearch.yml for ELasticSearch data backup/resistor procedure. 

        the norm is not be root - but be "ubuntu" for example - see notes on https://wiki.onap.org/display/DW/LOG+Meeting+Minutes+2018-06-26

       

       [elasticsearch@ocs-log-elasticsearch-7f4cf4b887-n2nv6 config]$ pwd

      /usr/share/elasticsearch/config

      [elasticsearch@ocs-log-elasticsearch-7f4cf4b887-n2nv6 config]$ ls -la
      total 36
      drwxr-xr-x 1 elasticsearch elasticsearch 4096 Jun 19 20:03 .
      drwx------ 1 elasticsearch elasticsearch 4096 Jun 19 19:56 ..

      rw-rr- 1 root          root          5711 Jun 11 18:57 elasticsearch.yml
      drwxr-x--- 2 elasticsearch elasticsearch 4096 Jul  6  2017 ingest-geoip
      rw-rw--- 1 elasticsearch elasticsearch 3117 Jun 30  2017 jvm.options
      rw-rw-r- 1 elasticsearch elasticsearch  272 Jul  6  2017 log4j2.properties
      drwxr-xr-x 2 elasticsearch elasticsearch 4096 Jun 11 18:58 scripts
      drwxr-x--- 1 elasticsearch elasticsearch 4096 Jul  6  2017 x-pack

      Note: 20180807: Kubernetes 1.9 will force a RO filesystem again as part of a security fix
      https://github.com/kubernetes/kubernetes/issues/62099

      Also ran into mkhinda's page via a google search
      https://wiki.onap.org/pages/viewpage.action?pageId=29787473

            michaelobrien michaelobrien
            st2373 st2373
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: