Skip to content

Commit e8cce1e

Browse files
committed
first pass of SLs for CLF. No openshift documentation exists yet.
1 parent 4e152c4 commit e8cce1e

6 files changed

+91
-0
lines changed
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to CloudWatch is failing due to insufficient permissions on the KMS key used to encrypt your CloudWatch Log Group. The Red Hat log forwarding service is unable to write encrypted log events to your CloudWatch Log Group. Please ensure that your KMS key policy allows the Red Hat log distribution role to use the key for encryption operations (kms:Decrypt, kms:GenerateDataKey).",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/encrypt-log-data-kms.html",
9+
"https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-modifying-external-accounts.html"
10+
],
11+
"internal_only": false,
12+
"_tags": [
13+
"sop_LogForwarding_CloudWatchDeliveryFailures"
14+
]
15+
}
16+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to CloudWatch is failing because the configured destination CloudWatch Log Group cannot be found. The log group may have been deleted or the log group name in the log forwarding configuration may be incorrect. Please verify that the destination CloudWatch Log Group exists in your AWS account. If the log group was deleted, please recreate it and ensure the log group resource policy allows the Red Hat log distribution role to perform CreateLogStream and PutLogEvents operations.",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CloudWatchLogsCrossAccountPolicy.html"
9+
],
10+
"internal_only": false,
11+
"_tags": [
12+
"sop_LogForwarding_CloudWatchDeliveryFailures"
13+
]
14+
}
15+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to CloudWatch is failing due to insufficient permissions on your CloudWatch Log Group. The Red Hat log forwarding service is unable to deliver logs to your CloudWatch Log Group. Please ensure that your CloudWatch Log Group resource policy allows the Red Hat log distribution role to perform CreateLogStream and PutLogEvents operations. For cross-account log delivery, a resource policy must be configured on your CloudWatch Log Group.",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CloudWatchLogsCrossAccountPolicy.html"
9+
],
10+
"internal_only": false,
11+
"_tags": [
12+
"sop_LogForwarding_CloudWatchDeliveryFailures"
13+
]
14+
}
15+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to S3 is failing because the configured destination S3 bucket cannot be found. The bucket may have been deleted or the bucket name in the log forwarding configuration may be incorrect. Please verify that the destination S3 bucket exists and is accessible. If the bucket was deleted, please recreate it and ensure the bucket policy allows the Red Hat log distribution role to perform PutObject and PutObjectAcl operations.",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-policies.html"
9+
],
10+
"internal_only": false,
11+
"_tags": [
12+
"sop_LogForwarding_S3PermissionIssues"
13+
]
14+
}
15+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to S3 is failing due to insufficient permissions on your S3 bucket. The Red Hat log forwarding service is unable to deliver logs to your S3 bucket. Please ensure that your S3 bucket policy allows the Red Hat log distribution role to perform PutObject and PutObjectAcl operations. Your bucket policy must include a statement that grants access to the Red Hat management role ARN.",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-policies.html"
9+
],
10+
"internal_only": false,
11+
"_tags": [
12+
"sop_LogForwarding_S3PermissionIssues"
13+
]
14+
}
15+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
{
2+
"severity": "Major",
3+
"service_name": "SREManualAction",
4+
"log_type": "cluster-configuration",
5+
"summary": "Log forwarding failed, action required",
6+
"description": "Your cluster's log forwarding to S3 is failing due to insufficient permissions on the KMS key used to encrypt your S3 bucket. The Red Hat log forwarding service is unable to write encrypted objects to your S3 bucket. Please ensure that your KMS key policy allows the Red Hat log distribution role to use the key for encryption operations (kms:Decrypt, kms:GenerateDataKey).",
7+
"doc_references": [
8+
"https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-modifying-external-accounts.html"
9+
],
10+
"internal_only": false,
11+
"_tags": [
12+
"sop_LogForwarding_S3PermissionIssues"
13+
]
14+
}
15+

0 commit comments

Comments
 (0)