Skip to content

v3.4.1

Choose a tag to compare

@EvSecDev EvSecDev released this 21 Jan 03:20
· 157 commits to main since this release
0ec1548

✅ Added

  • Adhoc script execution
  • Adhoc command execution
  • New repository default values if none are specified
  • Ability for remote/local/hosts override arguments to read CSVs from files using file URI scheme
  • File/Host override wildcard endings (like UniversalConfs_SSH/* or DBServer0*)
  • Seed repository can now use --remote-files to automatically download a list of files from a remote host into repository
  • SCP file transfer as main transfer method for deployments
  • Ability for --max-conns argument to disable concurrency if set to 1 (for testing deployments via single host first)

🔄 Changed

  • Installation script code moved into go code base
  • Global configuration variables into a single config struct to better define configuration options when referencing elsewhere in program
  • Seed repository and any user prompts to not log to journald
  • Repository file validation function to have simpler and clearer variable names
  • Filter hosts and files function to exclude the creation of deniedUniversalFiles (moved to dedicated function in predeploy step)
  • Dry-run termination point to be inside SSH deployment function allow for testing of multi-threadedness

❌ Removed

  • All standard output prints from being logged to journald
  • Installation script
  • Requirement for sftp subsystems on remote SSH servers
  • ReloadRequired JSON object from file metadata header (backwards compatible with old metadata header, but the ReloadRequired boolean is no longer functional)
  • README warning about sharing known_hosts file with other SSH clients (issue is resolved)
  • Manual known_hosts hashing when writing new entries (now using external package)

🔨 Fixed

  • During a deployment, if a program mistakenly writes stdout messages to stderr but otherwise exits with status code 0 deployment would still abort (fixed by ensuring deployment is only aborted if stderr has some data and exit code is non-zero)
  • If deploying /etc/sudoers, deployment would fail because sudoers would be owned by login user and unable to change owner/group on the file (fixed by changing owner/permissions on the temporary buffer file then moving it into place)
  • Specifying remote hosts/files or local files would not work (fixed by assigning csv's directly back into original variable when checking for URIs in override arguments)
  • Failtracker would fail to write due to using the wrong path (fixed by retrieving the main configs directory to join with faltracker file name)
  • Deployment of configs that required reload would always run reload commands even if file was identical or an error was encountered (fixed by skipping reloads if any one file encountered error or hash with local matches)
  • Per-host post deployment metrics would show a higher number of configs than what was actually changed on the remote host (fixed by decrementing a counter of total files requiring reload to use as per reload group metric for deployed configs)
  • More than one host universal override would not be recognized during a deployment (fixed by initializing universal map only if the key didn't exist)
  • Seed repository function would cause a panic when in dry-run mode (fixed by moving retireval of global host config to after host secrets retrieval)

ℹ️ Instructions

  • Please refer to the README.md file for instructions