[aap_containerized] Add missing components, fix secret masking gaps#4274
Merged
TurboTurtle merged 1 commit intososreport:mainfrom Apr 4, 2026
Merged
Conversation
|
Congratulations! One of the builds has completed. 🍾 You can install the built RPMs by following these steps:
Please note that the RPMs should be used only in a testing environment. |
pmoravec
approved these changes
Mar 17, 2026
Contributor
|
Thanks! Just a nitpick to
You can (try to) skip the plugopt |
TurboTurtle
reviewed
Mar 17, 2026
Member
TurboTurtle
left a comment
There was a problem hiding this comment.
When submitting AI-assisted changes, please make sure to follow our Contribution Guidelines, including with commit message formatting and not nuking the PR template provided.
- Fix typo: receptorclt -> receptorctl (replaced with receptor --version since receptorctl is not in the container) - Add pod_cmds for automation-hub-api (pulpcore-manager), automation-gateway-proxy (envoy), and postgresql (psql, pg_isready) - Add forbidden paths for newer components: lightspeed, ansiblemcp, gatewayproxy, pcp, and hub symmetric keys - Add SECRET_KEY file exclusions for controller, eda, gateway, lightspeed - Add secret masking for controller DB password (conf.d/postgres.py), hub DB password and cloud storage keys (AZURE_ACCOUNT_KEY, AWS_SECRET_ACCESS_KEY), and redis ACL password hashes - Add process signatures for hub (gunicorn pulpcore), receptor, and metrics-service to check_enabled Assisted-by: Claude Signed-off-by: Lucas Benedito <lbenedit@redhat.com>
f38c830 to
12972d1
Compare
Contributor
Author
|
My apologies for missing the community guidelines format for the PR summary. I've updated it accordingly. |
pmoravec
approved these changes
Mar 17, 2026
TurboTurtle
approved these changes
Apr 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
aap_containerizedplugin was missing coverage for several AAP components, had a typo in a command, and lacked secret masking for some configuration files.Bug fix:
receptorclt→receptorctl(and replace withreceptor --versionsincereceptorctlis not available inside the receptor container)New component coverage (pod_cmds):
automation-hub-api:pulpcore-manager --version,pulpcore-manager showmigrationsautomation-gateway-proxy:envoy --versionpostgresql:psql --version,pg_isreadyForbidden paths (cert/key/secret exclusion):
SECRET_KEYfiles for controller, eda, gateway, lightspeedhub/etc/keys/*.keyfor symmetric encryption keysSecret masking (postproc):
conf.d/postgres.py(triple-quoted format)AZURE_ACCOUNT_KEY,AWS_SECRET_ACCESS_KEYredis-users.aclProcess detection (check_enabled):
gunicorn pulpcore.app.wsgi(hub)receptor --configmetrics-service run