-
Notifications
You must be signed in to change notification settings - Fork 609
initial guide on fapolidy and firewalld #8598
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
Newest code from mattermost has been published to preview environment for Git SHA 0d85213 |
bgardner8008
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This looks good to me, regarding the RTCD components.
|
|
||
| **Configuration steps:** | ||
|
|
||
| For complete firewalld and fapolicyd configuration instructions, including troubleshooting steps and example rules, see the [RHEL deployment guide](https://docs.mattermost.com/deploy/server/deploy-rhel.html). The guide includes: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Let's link to the current home of the RHEL deployment guide on GitHub. We can update this link once that content moves over to the Product Docs site.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is linking for the fapolicy stuff that doesn't live on github that's in the rhel docs
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
OK. In the generated preview, that URL isn't resolving as expected. This will work: https://docs.mattermost.com/deployment-guide/server/deploy-linux.html#itab--RHEL-CentOS--0_1-RHEL-CentOS
| - `A Sysadmin's Guide to SELinux: 42 Answers to the Big Questions <https://opensource.com/article/18/7/sysadmin-guide-selinux>`_ | ||
| - `Mastering SELinux: A Comprehensive Guide to Linux Security <https://srivastavayushmaan1347.medium.com/mastering-selinux-a-comprehensive-guide-to-linux-security-8bed9976da88>`_ | ||
|
|
||
| .. important:: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
After viewing the generated preview, I'd like to propose an update to the way we're organizing and conveying these details. @coltoneshaw - Would you be open to me converting these Important callouts into tabbed content?
Under Step 5: Set up the server, we'd have tabs for:
- Modify SELinux settings
- Configure firewalld for government hardened environments
- Configure fapolicyd for government hardened environments
I'd shorten the tabs name for scannability.
If you agree, I'll commit changes to this PR directly.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think i did this. let me see what it looks like when generated. good suggestion!
|
Newest code from mattermost has been published to preview environment for Git SHA 0f24709 |
Summary
Added docs on deploying fapolicyd and firewalld to the core rhel docs and a note in the rtcd docs.