Template:Kickstart-Policy
From The Linux Source
- Approval (by Head of Security Team) is required before creating any non-kickstart or non-company-approved standard Linux or Unix OS installation.
- Installation of company approved kickstart OS image must be used to create a standard Linux image.
- New installs must all be 64bit CentOS 6 (or newer) unless there is a special 3rd party requirement that it has to be 32bit. 32bit systems will also need an approval.
- Kickstart creates a minimal OS install, plus a few approved packages for troubleshooting purposes.
- Our standard is to allocate all available/remaining space to /home, with company applications and support software run from /home (see step 6 in the Running Kickstart section under Kickstart for additional details), to isolate disk usage of additional process/applications from OS processes & logs.
- Kickstart incorporates standardized partitioning/configuration/packages/security settings/etc.
- Systems must use a central DNS/NTP/MAIL/Proxy for the Data Center they are in.
- Systems must be attached to spacewalk and a central logging server.