Infrastructure Credentials & Password Hardening
This operational reference provides the hardening guidelines and runbooks for eliminating default credentials and establishing zero-trust credential hygiene across the Okustera cloud platform.
It addresses both Deployment-Time Hardening (Day-0/1) and Post-Installation Lifecycle Rotation (Day-2).
Hardening Invariants
In accordance with the Okustera Security Architecture and ISO/IEC 27001 ISMS standards:
- Zero Default Passwords: No infrastructure component (RabbitMQ, MariaDB, Keystone, Docker Registry, Memcached) may operate with vendor-default or upstream chart fallback passwords (
password,admin, etc.). - Template Sanitation: Placeholder tokens (e.g.
OMC_*_SECURE_PASSWORD) must never be deployed to production workloads or committed to version control. - Cryptographic Entropy: Passwords must be generated with at least 192 bits of entropy (
openssl rand -hex 24or Barbican KMS generation). - Least-Privilege Network Exposure: Internal brokers, databases, and caches must never bind to public interfaces (
0.0.0.0) or expose management consoles via unauthenticated ingress routes.
1. Installation Stage: Pre-Deployment Automated Hardening
During automated installation, the platform orchestrator generates unique secrets prior to deploying Helm releases:
# Automated secret generation
SECRETS_FILE="infrastructure/undercloud/openstack-helm/values-poc/secrets.yaml"
umask 077
cat <<EOF > "${SECRETS_FILE}"
endpoints:
identity:
auth:
admin:
password: "$(openssl rand -hex 24)"
oslo_db:
auth:
admin:
password: "$(openssl rand -hex 24)"
oslo_messaging:
auth:
admin:
password: "$(openssl rand -hex 24)"
EOF
chmod 600 "${SECRETS_FILE}"
Helm deployment commands pass --values "${SECRETS_FILE}" to override upstream chart defaults across all service definitions.
2. Post-Installation: Day-2 Credential Rotation Runbooks
When credentials need to be updated or rotated on a running cluster:
RabbitMQ Broker Rotation
- Update Live Broker:
kubectl -n openstack exec rabbitmq-rabbitmq-0 -c rabbitmq -- \rabbitmqctl change_password rabbitmq "<NEW_PASSWORD>"
- Patch Kubernetes Secret:
kubectl -n openstack patch secret rabbitmq-admin-user --type='json' -p="[{\"op\": \"replace\", \"path\": \"/data/RABBITMQ_ADMIN_PASSWORD\", \"value\": \"$(echo -n '<NEW_PASSWORD>' | base64)\"}]"
- Restart Dependent Services:
kubectl -n openstack rollout restart deployment/nova-api-osapi deployment/neutron-server deployment/cinder-api
MariaDB Galera Rotation
- Update User Accounts in Database:
kubectl -n openstack exec mariadb-server-0 -c mariadb -- mysql -uroot -p<CURRENT_ROOT_PASS> -e "ALTER USER 'root'@'%' IDENTIFIED BY '<NEW_ROOT_PASS>';ALTER USER 'nova'@'%' IDENTIFIED BY '<NEW_NOVA_PASS>';FLUSH PRIVILEGES;"
- Update Secret & ConfigMaps:
kubectl -n openstack patch secret mariadb-dbadmin-password --type='json' -p="[{\"op\": \"replace\", \"path\": \"/data/MYSQL_DBADMIN_PASSWORD\", \"value\": \"$(echo -n '<NEW_ROOT_PASS>' | base64)\"}]"
- Restart OpenStack Daemons:
kubectl -n openstack rollout restart deployment/keystone-api deployment/glance-api deployment/cinder-api
Keystone Identity & Service Users
- Rotate Keystone Admin & Service Users:
openstack user set --password "<NEW_ADMIN_PASSWORD>" adminopenstack user set --domain service --password "<NEW_SERVICE_PASSWORD>" nova
- Update Client OpenRC Files:
Update
admin-openrc.shand ensure file permissions are restricted to0600(chmod 600 admin-openrc.sh). - Purge Test Users:
openstack user delete keystone-test glance-test nova-test neutron-test cinder-test
3. Automated Hardening Audit
Run the platform compliance check to verify that all default accounts are secured:
# Verify no service responds to unauthenticated or default credentials
curl -s -u "${TEST_USER}:${TEST_PASSWORD}" -H "Host: rabbitmq-mgr-7b1733" http://127.0.0.1/api/whoami
# Expected result: HTTP 401 / 403 or non-200 response
For complete technical specifications and script templates, consult the Credentials & Password Hardening Guide (docs/credentials_and_password_hardening_guide.md) in the core repository.