azvyagintsev
|
75a4eb54a6
|
Disable cis-3-3-3 rule
Change-Id: I956da1f26e500eae693827ed5dce0f7e65e291bc
Closes-Bug: PROD-22520 (PROD:22520)
|
6 年之前 |
Dmitry Teselkin
|
ad85db09b0
|
Remove non-existent CIS items
Change-Id: I91bfb8e2a06fc0499addd376db9e38483a6756d0
|
6 年之前 |
Dmitry Teselkin
|
af730f9602
|
CIS compliance (sysctl, limits)
* CIS 1.5.1 Ensure core dumps are restricted
* CIS 1.5.3 Ensure address space layout randomization (ASLR) is enabled
* CIS 3.1.2 Ensure packet redirect sending is disabled
* CIS 3.2.1 Ensure source routed packets are not accepted
* CIS 3.2.2 Ensure ICMP redirects are not accepted
* CIS 3.2.3 Ensure secure ICMP redirects are not accepted
* CIS 3.2.4 Ensure suspicious packets are logged
* CIS 3.2.5 Ensure broadcast ICMP requests are ignored
* CIS 3.2.6 Ensure bogus ICMP responses are ignored
* CIS 3.2.7 Ensure Reverse Path Filtering is enabled
* CIS 3.2.8 Ensure TCP SYN Cookies is enabled
All sysctls are valid for Ubuntu 14.04, Ubuntu 16.04.
Change-Id: I48f34c55d97a78c253d4810db46b2a04ff5c0c1a
|
6 年之前 |
Aleksey Zvyagintsev
|
cf1b5b322a
|
Revert "CIS compliance (modprobe.d)"
This reverts commit d87f461319 .
Change-Id: If175b29f2e130ecf5041e7b0be20f15485089ffa
|
6 年之前 |
Dmitry Teselkin
|
d87f461319
|
CIS compliance (modprobe.d)
* CIS 1.1.1.1 Ensure mounting of cramfs filesystems is disabled
* CIS 1.1.1.2 Ensure mounting of freevxfs filesystems is disabled
* CIS 1.1.1.3 Ensure mounting of jffs2 filesystems is disabled
* CIS 1.1.1.4 Ensure mounting of hfs filesystems is disabled
* CIS 1.1.1.5 Ensure mounting of hfsplus filesystems is disabled
* CIS 1.1.1.6 Ensure mounting of squashfs filesystems is disabled
* CIS 1.1.1.7 Ensure mounting of udf filesystems is disabled
* CIS 1.1.1.8 Ensure mounting of FAT filesystems is disabled
* CIS 3.5.1 Ensure DCCP is disabled
* CIS 3.5.2 Ensure SCTP is disabled
* CIS 3.5.3 Ensure RDS is disabled
* CIS 3.5.4 Ensure TIPC is disabled
Related-Prod: PROD-20756
Related-Prod: PROD-20757
Related-Prod: PROD-20758
Related-Prod: PROD-20759
Change-Id: I719984829978caf0401e78daaabf1adfb0d1cfdf
|
6 年之前 |
Dmitry Teselkin
|
cc7263a275
|
CIS 3.3.3 Ensure IPv6 is disabled
Related-Prod: PROD-20755
Change-Id: I44cc3bdb4a0436ff17f790a828d03697b89d3520
|
6 年之前 |
Bartosz Kupidura
|
19330f5e9e
|
Add fluentd support
Change-Id: I64a93135daebe7d55430adc51de2c9186c7a5ad7
|
7 年之前 |
Simon Pasquier
|
1546e4c8c2
|
Disable Sensu support by default
Change-Id: I4711aaa954fbbf8f02b2731e6ae62db127ed21be
|
7 年之前 |
Jiri Broulik
|
25839cca97
|
purging repos
|
7 年之前 |
Bartosz Kupidura
|
0bd8565876
|
Add support for prometheus
Change-Id: I66576b4ed40ef160c5f13747a908f018f252b6b4
|
7 年之前 |
Bartosz Kupidura
|
df9b40d973
|
Add telegraf support
Change-Id: I03bed44bafdebbcd22f487e59ef0de45dfbf3463
|
7 年之前 |
Guillaume Thouvenin
|
e29d0a4f77
|
Provides Grafana dashboard
|
8 年之前 |
Ales Komarek
|
3a9faa53ed
|
Container metadata
|
8 年之前 |
Ales Komarek
|
2791e48cc7
|
Moved support scripts around
|
9 年之前 |
Ales Komarek
|
cbe08a2eec
|
New parameteters
|
9 年之前 |
jan kaufman
|
a24b9af5ec
|
disable heka logging for now
|
9 年之前 |
Ales Komarek
|
d8fee8492b
|
Monitoring metadata, mount dont create fs for nfs
|
9 年之前 |
Filip Pytloun
|
f5383a44be
|
Initial commit
|
9 年之前 |