0.7.0
Some checks failed
Lint / test (push) Waiting to run
CI / test (push) Successful in 54s
CI / test (almalinux, docker.io/library/almalinux:9, python3.11) (push) Successful in 11m34s
CI / test (debian, docker.io/library/debian:13, python3) (push) Has been cancelled

This commit is contained in:
Miguel Jacq 2026-07-05 10:58:33 +10:00
parent 1148b34bce
commit 7d54696402
Signed by: mig5
GPG key ID: 03906B4110AAD3B8
4 changed files with 37 additions and 3 deletions

View file

@ -1,4 +1,4 @@
%global upstream_version 0.6.0
%global upstream_version 0.7.0
Name: enroll
Version: %{upstream_version}
@ -43,6 +43,21 @@ Enroll a server's running state retrospectively into Ansible.
%{_bindir}/enroll
%changelog
* Sun Jul 05 2026 Miguel Jacq <mig@mig5.net> - %{version}-%{release}
- BREAKING CHANGE: Remove the `enroll diff --enforce` option. Enroll no longer applies the old harvest state locally to repair drift; this avoids the risk of enforcing a potentially malicious or tampered harvest. To restore baseline state, regenerate a manifest from the trusted harvest and apply it yourself, or compare two `enroll diff` runs and act on the result.
- BREAKING CHANGE: Group all package and systemd-unit roles into Debian Section/RPM Group roles by default, including managed config files and unit state. This mode is not used if `--fqdn` or `--no-common-roles` is set, in which case, the traditional behaviour of preserving one role per package/unit is used instead.
- BREAKING CHANGE: Only capture user-specific .bashrc style files when using `--dangerous` mode, in case they contain sensitive env vars.
- BREAKING CHANGE: Don't allow reading `.enroll.ini` in the CWD. Use only the ENROLL_CONFIG env var, an explicit `--config` path or else the XDG default location (or `~/.config/enroll/enroll.ini` if `XDG_CONFIG_HOME` is not set).
- Detect active sysctl parameters and write them to a `/etc/sysctl.d/99-enroll.conf` file
- Use `no_log` on systemd unit interrogations to suppress potential sensitive output when applying Ansible
- Support for detecting Docker and Podman images and enforcing their presence (by SHA256 hash).
- Add support for detecting Flatpaks and Snaps.
- Stricter validation of harvests to ensure that they meet the schema and don't contain unsafe artifacts (e.g symlinks pointing outside the artifact tree)
- Perform harvest validation before trying to manifest from it.
- Stricter validation on FQDN name in multisite mode.
- Strict check of `$PATH` when running harvest as root, in case it could lead to execution of unsafe binaries during harvest. Override with `--assume-safe-path` for non-interactive or CI purposes.
- Stricter validation of the destination dirs that harvest or manifest write to, to prevent writing to a different user-controlled area. Stricter permissions on the output dirs too.
- Lots of hardening across the whole codebase and integration with Jinjaturtle.
* Thu May 14 2026 Miguel Jacq <mig@mig5.net> - %{version}-%{release}
- Add support for capturing ipset and iptables configuration files
- Add support for generating ipset and iptables configuration files from runtime, if the former weren't present ('firewall_runtime' role)