feat(roles/system_update): add Rocky Linux security update lane#258
Merged
Conversation
Add a second systemd timer (twice a day by default) that installs only Rocky Linux security hot-fixes from the dedicated `security` repository (provided by repo_baseos), isolated from the regular weekly update lane via --disablerepo/--enablerepo. Reboots the host when needed; the reboot time is steered per host group via system_update__security_reboot_time__* (immediate on test hosts, deferred on production hosts). Enabled by default; a no-op where the security repository is not enabled, and can be turned off with system_update__security_enabled: false. Rocky Linux only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds a security lane to the
system_updaterole for Rocky Linux: a second systemd timer (security-update, twice a day by default) that installs only Rocky Linux security hot-fixes from the dedicatedsecurityrepository and reboots the host if needed.Why
The
securityrepository (added torepo_baseos, enabled by default) ships emergency hot-fixes for critical, actively exploited CVEs ahead of the regular Red Hat upstream patch. Enabling the repo alone means those fixes only land on the next weeklysystem_updaterun (up to ~7 days). This lane applies them daily, while the regular update lane stays on its weekly schedule.Details
dnf --disablerepo="*" --enablerepo="security".system_update__security_reboot_time__*(immediate on test hosts, deferred e.g.19:00on production hosts).securityrepository is not enabled (respects an opt-out viarepo_baseos__security_repo_enabled: false). Rocky Linux only (distribution == "Rocky").securityrepository provided byrepo_baseos; this PR does not touch the repo definition itself.