fix(azurelinux-release): harden cloud ssh defaults - #18442
Draft
Tobias Brick (tobiasb-ms) wants to merge 1 commit into
Draft
fix(azurelinux-release): harden cloud ssh defaults#18442Tobias Brick (tobiasb-ms) wants to merge 1 commit into
Tobias Brick (tobiasb-ms) wants to merge 1 commit into
Conversation
Configure the Azure Linux cloud variant to satisfy CIS SSH access, banner, authentication, connection, and MAC requirements. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ba5f8625-80e3-4137-9482-a9bc582c9e99
Contributor
There was a problem hiding this comment.
Pull request overview
Hardens SSH defaults for Azure Linux cloud images to satisfy targeted CIS controls.
Changes:
- Adds cloud-specific SSH access, authentication, banner, MAC, and connection limits.
- Packages the policy in
azurelinux-release-cloud. - Updates the release, rendered output, and component lock.
Reviewed changes
Copilot reviewed 4 out of 5 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
base/comps/azurelinux-release/30-azurelinux-cis.conf |
Defines cloud SSH hardening policy. |
base/comps/azurelinux-release/azurelinux-release.spec |
Packages the policy and bumps the release. |
specs/a/azurelinux-release/30-azurelinux-cis.conf |
Contains the rendered policy. |
specs/a/azurelinux-release/azurelinux-release.spec |
Contains the updated rendered spec. |
locks/azurelinux-release.lock |
Refreshes the component fingerprint. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
azurelinux-release-cloudTesting
azurelinux-releasesuccessfully withazldev comp build -p azurelinux-releaseazurelinux-release-cloudandsshd -taccepts the configurationsshd -Tin a mock chroot