Skip to content

Conversation

@lunkan93
Copy link
Contributor

@lunkan93 lunkan93 commented Nov 21, 2024

Warning

This is a public repository, ensure not to disclose:

  • personal data beyond what is necessary for interacting with this pull request, nor
  • business confidential information, such as customer names.

What kind of PR is this?

Required: Mark one of the following that is applicable:

  • kind/feature
  • kind/improvement
  • kind/deprecation
  • kind/documentation
  • kind/clean-up
  • kind/bug
  • kind/other

Optional: Mark one or more of the following that are applicable:

Important

Breaking changes should be marked kind/admin-change or kind/dev-change depending on type
Critical security fixes should be marked with kind/security

  • kind/admin-change
  • kind/dev-change
  • kind/security
  • kind/adr

Security notice

OpenSearch Dashboards was upgraded to 2.17.1 which mitigates CVE-2024-45801

What does this PR do / why do we need this PR?

Upgrades OpenSearch to Chart Version 2.26.1 and OpenSearch Dashboards to Chart Version 2.24.1, which upgrades the App Version to 2.17.1. This mitigates CVE-2024-45801, which the current version of dompurify used in OpenSearch Dashboards is affected by. It also adds a fix for the "red screen" bug present for newer versions of Google Chrome. This PR also changes the name of the index that OpenSearch Dashboards uses to store saved objects (Visualizations e.t.c..) back to the default .kibana, as this name override was causing issues with System Index permissions, preventing access from all regular users including admin and OpenSearch Dashboards. Changing this back to the default value also fixes the Reporting feature in OpenSearch Dashboards which has not been functional previously.

  • Fixes #

Information to reviewers

Checklist

  • Proper commit message prefix on all commits
  • Change checks:
    • The change is transparent
    • The change is disruptive
    • The change requires no migration steps
    • The change requires migration steps
    • The change upgrades CRDs
    • The change updates the config and the schema
  • Documentation checks:
  • Metrics checks:
    • The metrics are still exposed and present in Grafana after the change
    • The metrics names didn't change (Grafana dashboards and Prometheus alerts are not affected)
    • The metrics names did change (Grafana dashboards and Prometheus alerts were fixed)
  • Logs checks:
    • The logs do not show any errors after the change
  • Pod Security Policy checks:
    • Any changed pod is covered by Pod Security Admission
    • Any changed pod is covered by Gatekeeper Pod Security Policies
    • The change does not cause any pods to be blocked by Pod Security Admission or Policies
  • Network Policy checks:
    • Any changed pod is covered by Network Policies
    • The change does not cause any dropped packets in the NetworkPolicy Dashboard
  • Audit checks:
    • The change does not cause any unnecessary Kubernetes audit events
    • The change requires changes to Kubernetes audit policy
  • Falco checks:
    • The change does not cause any alerts to be generated by Falco
  • Bug checks:
    • The bug fix is covered by regression tests

@lunkan93 lunkan93 force-pushed the simonl/upgrade-opensearch-2.17.1 branch from a2969b9 to 6373d01 Compare November 22, 2024 11:57
@lunkan93 lunkan93 changed the title Simonl/upgrade opensearch 2.17.1 Upgrade OpenSearch to v2.17.1 Nov 29, 2024
@lunkan93 lunkan93 force-pushed the simonl/upgrade-opensearch-2.17.1 branch from 8d5566a to 076e9fe Compare November 29, 2024 11:40
@lunkan93 lunkan93 self-assigned this Nov 29, 2024
@lunkan93 lunkan93 added app/opensearch OpenSearch - Logs Storage app/opensearch-dashboards OpenSearch Dashboards - Logs Visualisation labels Nov 29, 2024
@lunkan93 lunkan93 marked this pull request as ready for review December 2, 2024 08:31
@lunkan93 lunkan93 requested review from a team as code owners December 2, 2024 08:31
aarnq
aarnq previously requested changes Dec 2, 2024
Copy link
Contributor

@aarnq aarnq left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ensure that the migration only performs the specialised steps if we have a version diff on OpenSearch.
Else it should do a generic apply to ensure that is still is up to date in terms of config.

Copy link
Contributor

@robinAwallace robinAwallace left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work, I know there where a lot of small things to figure out for this migration 😄 LGTM 👍

@aarnq aarnq dismissed their stale review December 3, 2024 10:31

Conditional migration fixed.

Copy link

@salehsedghpour salehsedghpour left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🎉

Copy link
Contributor

@aarnq aarnq left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just one question else it LGTM.

@lunkan93 lunkan93 requested a review from OlleLarsson December 6, 2024 13:50
Copy link
Contributor

@OlleLarsson OlleLarsson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks nice to me, just have some small comments

@lunkan93 lunkan93 requested a review from OlleLarsson December 12, 2024 09:10
@lunkan93 lunkan93 force-pushed the simonl/upgrade-opensearch-2.17.1 branch from 2b43399 to 19b8539 Compare December 12, 2024 10:22
@lunkan93 lunkan93 merged commit c5350f5 into main Dec 12, 2024
12 checks passed
@lunkan93 lunkan93 deleted the simonl/upgrade-opensearch-2.17.1 branch December 12, 2024 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

app/opensearch OpenSearch - Logs Storage app/opensearch-dashboards OpenSearch Dashboards - Logs Visualisation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants