mirror of
				https://github.com/TommyTran732/Fedora-CoreOS-Ignition.git
				synced 2025-11-04 11:08:35 +01:00 
			
		
		
		
	Use systemd units section to disable kdump and debug-shell
Signed-off-by: Tommy <contact@tommytran.io>
This commit is contained in:
		@@ -191,14 +191,6 @@
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/multi-user.target.wants/tuned.service",
 | 
			
		||||
        "target": "/usr/lib/systemd/system/tuned.service"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/kdump.service",
 | 
			
		||||
        "target": "/dev/null"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/debug-shell.service",
 | 
			
		||||
        "target": "/dev/null"
 | 
			
		||||
      }
 | 
			
		||||
    ]
 | 
			
		||||
  },
 | 
			
		||||
@@ -243,6 +235,16 @@
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": true,
 | 
			
		||||
        "name": "sshd.socket"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": false,
 | 
			
		||||
        "mask": true,
 | 
			
		||||
        "name": "kdump.service"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": false,
 | 
			
		||||
        "mask": true,
 | 
			
		||||
        "name": "debug-shell.service"
 | 
			
		||||
      }
 | 
			
		||||
    ]
 | 
			
		||||
  }
 | 
			
		||||
 
 | 
			
		||||
@@ -100,6 +100,12 @@ systemd:
 | 
			
		||||
      enabled: false
 | 
			
		||||
    - name: sshd.socket
 | 
			
		||||
      enabled: true
 | 
			
		||||
    - name: kdump.service
 | 
			
		||||
      enabled: false
 | 
			
		||||
      mask: true
 | 
			
		||||
    - name: debug-shell.service
 | 
			
		||||
      enabled: false
 | 
			
		||||
      mask: true
 | 
			
		||||
storage:
 | 
			
		||||
  files:
 | 
			
		||||
    - path: /etc/zincati/config.d/51-rollout-wariness.toml
 | 
			
		||||
@@ -178,10 +184,6 @@ storage:
 | 
			
		||||
      target: /usr/lib/systemd/system/unbound.service
 | 
			
		||||
    - path: /etc/systemd/system/multi-user.target.wants/tuned.service
 | 
			
		||||
      target: /usr/lib/systemd/system/tuned.service
 | 
			
		||||
    - path: /etc/systemd/system/kdump.service
 | 
			
		||||
      target: /dev/null
 | 
			
		||||
    - path: /etc/systemd/system/debug-shell.service
 | 
			
		||||
      target: /dev/null
 | 
			
		||||
kernel_arguments:
 | 
			
		||||
  should_exist:
 | 
			
		||||
    - mitigations=auto,nosmt
 | 
			
		||||
 
 | 
			
		||||
@@ -217,14 +217,6 @@
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/multi-user.target.wants/tuned.service",
 | 
			
		||||
        "target": "/usr/lib/systemd/system/tuned.service"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/kdump.service",
 | 
			
		||||
        "target": "/dev/null"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "path": "/etc/systemd/system/debug-shell.service",
 | 
			
		||||
        "target": "/dev/null"
 | 
			
		||||
      }
 | 
			
		||||
    ]
 | 
			
		||||
  },
 | 
			
		||||
@@ -284,6 +276,16 @@
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": true,
 | 
			
		||||
        "name": "sshd.socket"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": false,
 | 
			
		||||
        "mask": true,
 | 
			
		||||
        "name": "kdump.service"
 | 
			
		||||
      },
 | 
			
		||||
      {
 | 
			
		||||
        "enabled": false,
 | 
			
		||||
        "mask": true,
 | 
			
		||||
        "name": "debug-shell.service"
 | 
			
		||||
      }
 | 
			
		||||
    ]
 | 
			
		||||
  }
 | 
			
		||||
 
 | 
			
		||||
@@ -157,6 +157,12 @@ systemd:
 | 
			
		||||
      enabled: false
 | 
			
		||||
    - name: sshd.socket
 | 
			
		||||
      enabled: true
 | 
			
		||||
    - name: kdump.service
 | 
			
		||||
      enabled: false
 | 
			
		||||
      mask: true
 | 
			
		||||
    - name: debug-shell.service
 | 
			
		||||
      enabled: false
 | 
			
		||||
      mask: true
 | 
			
		||||
storage:
 | 
			
		||||
  files:
 | 
			
		||||
    - path: /etc/zincati/config.d/51-rollout-wariness.toml
 | 
			
		||||
@@ -245,10 +251,6 @@ storage:
 | 
			
		||||
      target: /usr/lib/systemd/system/unbound.service
 | 
			
		||||
    - path: /etc/systemd/system/multi-user.target.wants/tuned.service
 | 
			
		||||
      target: /usr/lib/systemd/system/tuned.service
 | 
			
		||||
    - path: /etc/systemd/system/kdump.service
 | 
			
		||||
      target: /dev/null
 | 
			
		||||
    - path: /etc/systemd/system/debug-shell.service
 | 
			
		||||
      target: /dev/null
 | 
			
		||||
kernel_arguments:
 | 
			
		||||
  should_exist:
 | 
			
		||||
    - mitigations=auto,nosmt
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user