Skip to content

v1.6.0

Choose a tag to compare

@EvSecDev EvSecDev released this 06 Dec 23:30
· 179 commits to main since this release
6c2e323

Added

  • Controller dry-run option to test all actions and print relevant information before remote connections
  • Controller option to validate configuration file syntax and options
  • Controller pretty error output for deployment failures
  • Dedicated directory to store temporary backups of remote files before overwriting
  • Controller ability to override failure redeployment hosts
  • Controller ability to override automatic deployment files
  • Explicit garbage collection configuration options to controller new repository creation function
  • Deployer dry-run option to test server listener setup prior to opening a socket
  • Deployer option to validate configuration file syntax

Changed

  • Controller local file load function to condense commit file information maps into a single map
  • Controller seed repository default permissions for newly created files (mitigate leaking sensitive remote file contents to other users on local system)
  • Deployer install script to correct permissions of apparmor profile file after write
  • Controller git hook toggle code to dedicated function
  • Controller commit file metadata handling by using a dedicated structure in it's map instead of an interface
  • Controller SSH deployment function (minor code refactoring)
  • Tweaked controller global constant type assertions

Removed

  • Renaming existing remote configuration files to ".old" for temporary deployment backups
  • Controller requirement to have the manual-deploy argument when using the deploy-all argument
  • Deployer apparmor confinement of reload commands (Shifted responsibility for specific reload confinement to user after install)

Fixed

  • Some controller deployment reloads were failing because of systemd auto-restart limits (fixed by grouping deployment files by reload command and only reloading after all relevant files are deployed)
  • Controller would panic when seeding the repository and unable to read the root of the filesystem ("/") (fixed by returning from menu function immediately if directory read on "/" failed)
  • Controller would rollback repository when committing files in the root of the repository or in ignored directories (fixed by gracefully exiting deployment when no valid deployment files are present)
  • Git hook disable/enable argument would still print success even if it failed (fixed by ensuring error is not present before printing success message)
  • Installers would install apparmor profiles that did not allow read/write to the default remote temporary buffer file (fixed by unifying file names under install script variables)
  • Controller all-deploy would not deploy any files (fixed by checking raw override string length instead of file override array length)
  • Controller SSH remote public key checking was ignoring errors when reading user input prompt (fixed by checking for error in stdin reader)

Instructions

  • Please refer to the README.md file for instructions