|
44 | 44 | # audit record can reference an exact version — bump the version when the wording |
45 | 45 | # materially changes and a stored ack below it re-prompts. (The network-Redfish |
46 | 46 | # opt-in is a separate, sharper warning with an enforced delay — a later phase.) |
| 47 | +# |
| 48 | +# The VERSION spans ALL languages: every _HW_CONSENT_TEXT entry is the SAME warning, |
| 49 | +# v1, in a different language — they must stay semantically equivalent and be bumped |
| 50 | +# together. version + require_delay_seconds are injected by hw_consent_warning() so |
| 51 | +# they can never drift per-language. The acknowledged language is recorded alongside |
| 52 | +# the version at ack time (which exact text the user actually saw). |
47 | 53 | HW_CONSENT_VERSION = 1 |
48 | | -HW_CONSENT_WARNING = { |
49 | | - 'version': HW_CONSENT_VERSION, |
50 | | - 'require_delay_seconds': 0, # in-band: mandatory confirm, no forced wait (Redfish will use >0) |
51 | | - 'title': 'Enable in-band hardware monitoring (IPMI)', |
52 | | - 'summary': 'PegaProx will read hardware health directly on each node through its local IPMI interface.', |
53 | | - 'points': [ |
54 | | - 'Reads happen on the node over its local IPMI channel (/dev/ipmi0) — no BMC network credentials are stored, and the out-of-band management network is not accessed.', |
55 | | - 'Only read-only IPMI commands are issued (sensors, event log, FRU inventory, power). No power, virtual-media or firmware operations.', |
56 | | - 'If you enable installation, PegaProx will install the "ipmitool" package and may load the IPMI kernel modules on the node.', |
57 | | - 'On strictly hardened systems the local IPMI interface may be intentionally disabled under a least-functionality baseline. Enabling this here does not override that — where the interface is absent, PegaProx reports no data rather than re-enabling it.', |
58 | | - ], |
59 | | - 'compliance_note': 'Enabling this may be relevant to your least-functionality and BMC-hardening controls (e.g. CMMC / NIST 800-171 3.4.6 and 3.1.5, DISA STIG BMC/OOB guidance). Confirm with your compliance owner. This is not legal advice.', |
60 | | - 'confirm_label': 'I understand, and I accept responsibility for enabling this', |
| 54 | +HW_CONSENT_DELAY_SECONDS = 0 # in-band: mandatory confirm, no forced wait (Redfish will use >0) |
| 55 | + |
| 56 | +_HW_CONSENT_TEXT = { |
| 57 | + 'en': { |
| 58 | + 'title': 'Enable in-band hardware monitoring (IPMI)', |
| 59 | + 'summary': 'PegaProx will read hardware health directly on each node through its local IPMI interface.', |
| 60 | + 'points': [ |
| 61 | + 'Reads happen on the node over its local IPMI channel (/dev/ipmi0) — no BMC network credentials are stored, and the out-of-band management network is not accessed.', |
| 62 | + 'Only read-only IPMI commands are issued (sensors, event log, FRU inventory, power). No power, virtual-media or firmware operations.', |
| 63 | + 'If you enable installation, PegaProx will install the "ipmitool" package and may load the IPMI kernel modules on the node.', |
| 64 | + 'On strictly hardened systems the local IPMI interface may be intentionally disabled under a least-functionality baseline. Enabling this here does not override that — where the interface is absent, PegaProx reports no data rather than re-enabling it.', |
| 65 | + ], |
| 66 | + 'compliance_note': 'Enabling this may be relevant to your least-functionality and BMC-hardening controls (e.g. CMMC / NIST 800-171 3.4.6 and 3.1.5, DISA STIG BMC/OOB guidance). Confirm with your compliance owner. This is not legal advice.', |
| 67 | + 'confirm_label': 'I understand, and I accept responsibility for enabling this', |
| 68 | + }, |
| 69 | + 'de': { |
| 70 | + 'title': 'In-Band-Hardware-Überwachung (IPMI) aktivieren', |
| 71 | + 'summary': 'PegaProx liest den Hardware-Zustand direkt auf jedem Node über dessen lokale IPMI-Schnittstelle.', |
| 72 | + 'points': [ |
| 73 | + 'Die Lesevorgänge erfolgen auf dem Node über dessen lokalen IPMI-Kanal (/dev/ipmi0) — es werden keine BMC-Netzwerk-Zugangsdaten gespeichert, und auf das Out-of-Band-Management-Netzwerk wird nicht zugegriffen.', |
| 74 | + 'Es werden ausschließlich lesende IPMI-Befehle ausgeführt (Sensoren, Ereignisprotokoll, FRU-Inventar, Stromverbrauch). Keine Power-, Virtual-Media- oder Firmware-Operationen.', |
| 75 | + 'Wenn Sie die Installation aktivieren, installiert PegaProx das Paket „ipmitool“ und lädt ggf. die IPMI-Kernelmodule auf dem Node.', |
| 76 | + 'Auf streng gehärteten Systemen kann die lokale IPMI-Schnittstelle bewusst im Rahmen einer Least-Functionality-Baseline deaktiviert sein. Die Aktivierung hier hebt das nicht auf — wo die Schnittstelle fehlt, meldet PegaProx keine Daten, statt sie wieder zu aktivieren.', |
| 77 | + ], |
| 78 | + 'compliance_note': 'Die Aktivierung kann für Ihre Least-Functionality- und BMC-Härtungs-Kontrollen relevant sein (z. B. CMMC / NIST 800-171 3.4.6 und 3.1.5, DISA STIG BMC/OOB-Vorgaben). Stimmen Sie sich mit Ihrem Compliance-Verantwortlichen ab. Dies ist keine Rechtsberatung.', |
| 79 | + 'confirm_label': 'Ich verstehe dies und übernehme die Verantwortung für die Aktivierung', |
| 80 | + }, |
| 81 | + 'fr': { |
| 82 | + 'title': "Activer la surveillance matérielle en bande (IPMI)", |
| 83 | + 'summary': "PegaProx lira l'état du matériel directement sur chaque nœud via son interface IPMI locale.", |
| 84 | + 'points': [ |
| 85 | + "Les lectures s'effectuent sur le nœud via son canal IPMI local (/dev/ipmi0) — aucun identifiant réseau du BMC n'est stocké et le réseau de gestion hors bande n'est pas utilisé.", |
| 86 | + "Seules des commandes IPMI en lecture seule sont émises (capteurs, journal d'événements, inventaire FRU, consommation). Aucune opération d'alimentation, de média virtuel ou de micrologiciel.", |
| 87 | + "Si vous activez l'installation, PegaProx installera le paquet « ipmitool » et pourra charger les modules noyau IPMI sur le nœud.", |
| 88 | + "Sur les systèmes fortement durcis, l'interface IPMI locale peut être volontairement désactivée dans le cadre d'une base de moindre fonctionnalité. L'activer ici ne l'annule pas — là où l'interface est absente, PegaProx ne renvoie aucune donnée plutôt que de la réactiver.", |
| 89 | + ], |
| 90 | + 'compliance_note': "Cette activation peut concerner vos contrôles de moindre fonctionnalité et de durcissement du BMC (par ex. CMMC / NIST 800-171 3.4.6 et 3.1.5, recommandations DISA STIG BMC/OOB). Vérifiez avec votre responsable conformité. Ceci ne constitue pas un conseil juridique.", |
| 91 | + 'confirm_label': "Je comprends et j'accepte la responsabilité de cette activation", |
| 92 | + }, |
| 93 | + 'es': { |
| 94 | + 'title': 'Activar la supervisión de hardware en banda (IPMI)', |
| 95 | + 'summary': 'PegaProx leerá el estado del hardware directamente en cada nodo a través de su interfaz IPMI local.', |
| 96 | + 'points': [ |
| 97 | + 'Las lecturas se realizan en el nodo a través de su canal IPMI local (/dev/ipmi0): no se almacenan credenciales de red del BMC y no se accede a la red de gestión fuera de banda.', |
| 98 | + 'Solo se emiten comandos IPMI de solo lectura (sensores, registro de eventos, inventario FRU, consumo). Ninguna operación de alimentación, medios virtuales o firmware.', |
| 99 | + 'Si activa la instalación, PegaProx instalará el paquete «ipmitool» y podrá cargar los módulos del kernel IPMI en el nodo.', |
| 100 | + 'En sistemas muy reforzados, la interfaz IPMI local puede estar deshabilitada intencionadamente bajo una base de funcionalidad mínima. Activarla aquí no anula eso: donde la interfaz no existe, PegaProx no informa de ningún dato en lugar de reactivarla.', |
| 101 | + ], |
| 102 | + 'compliance_note': 'Activar esto puede ser relevante para sus controles de funcionalidad mínima y de refuerzo del BMC (p. ej., CMMC / NIST 800-171 3.4.6 y 3.1.5, directrices DISA STIG BMC/OOB). Confírmelo con su responsable de cumplimiento. Esto no es asesoramiento legal.', |
| 103 | + 'confirm_label': 'Entiendo y acepto la responsabilidad de activar esto', |
| 104 | + }, |
| 105 | + 'pt': { |
| 106 | + 'title': 'Ativar a monitorização de hardware em banda (IPMI)', |
| 107 | + 'summary': 'O PegaProx lerá o estado do hardware diretamente em cada nó através da sua interface IPMI local.', |
| 108 | + 'points': [ |
| 109 | + 'As leituras são feitas no nó através do seu canal IPMI local (/dev/ipmi0) — não são armazenadas credenciais de rede do BMC e a rede de gestão fora de banda não é acedida.', |
| 110 | + 'Apenas são emitidos comandos IPMI de leitura (sensores, registo de eventos, inventário FRU, consumo). Nenhuma operação de energia, media virtual ou firmware.', |
| 111 | + 'Se ativar a instalação, o PegaProx instalará o pacote «ipmitool» e poderá carregar os módulos de kernel IPMI no nó.', |
| 112 | + 'Em sistemas fortemente reforçados, a interface IPMI local pode estar intencionalmente desativada sob uma base de funcionalidade mínima. Ativá-la aqui não anula isso — onde a interface não existe, o PegaProx não devolve dados em vez de a reativar.', |
| 113 | + ], |
| 114 | + 'compliance_note': 'Ativar isto pode ser relevante para os seus controlos de funcionalidade mínima e de reforço do BMC (por ex., CMMC / NIST 800-171 3.4.6 e 3.1.5, orientações DISA STIG BMC/OOB). Confirme com o seu responsável de conformidade. Isto não constitui aconselhamento jurídico.', |
| 115 | + 'confirm_label': 'Compreendo e aceito a responsabilidade por ativar isto', |
| 116 | + }, |
| 117 | + 'ko': { |
| 118 | + 'title': '인밴드 하드웨어 모니터링(IPMI) 활성화', |
| 119 | + 'summary': 'PegaProx는 각 노드의 로컬 IPMI 인터페이스를 통해 하드웨어 상태를 직접 읽습니다.', |
| 120 | + 'points': [ |
| 121 | + '읽기는 노드의 로컬 IPMI 채널(/dev/ipmi0)을 통해 수행됩니다. BMC 네트워크 자격 증명은 저장되지 않으며, 대역 외 관리 네트워크에 접근하지 않습니다.', |
| 122 | + '읽기 전용 IPMI 명령만 실행됩니다(센서, 이벤트 로그, FRU 인벤토리, 전력). 전원, 가상 미디어 또는 펌웨어 작업은 수행하지 않습니다.', |
| 123 | + '설치를 활성화하면 PegaProx가 노드에 "ipmitool" 패키지를 설치하며, IPMI 커널 모듈을 로드할 수도 있습니다.', |
| 124 | + '강력하게 강화된 시스템에서는 최소 기능 기준에 따라 로컬 IPMI 인터페이스가 의도적으로 비활성화되어 있을 수 있습니다. 여기서 활성화하더라도 이를 무효화하지 않습니다. 인터페이스가 없는 경우 PegaProx는 이를 다시 활성화하지 않고 데이터를 보고하지 않습니다.', |
| 125 | + ], |
| 126 | + 'compliance_note': '이 기능을 활성화하는 것은 최소 기능 및 BMC 강화 통제(예: CMMC / NIST 800-171 3.4.6 및 3.1.5, DISA STIG BMC/OOB 지침)와 관련될 수 있습니다. 규정 준수 책임자와 확인하십시오. 이것은 법률 자문이 아닙니다.', |
| 127 | + 'confirm_label': '이해했으며 이 기능을 활성화하는 것에 대한 책임을 수락합니다', |
| 128 | + }, |
| 129 | + 'it': { |
| 130 | + 'title': "Abilitare il monitoraggio hardware in banda (IPMI)", |
| 131 | + 'summary': "PegaProx leggerà lo stato dell'hardware direttamente su ogni nodo tramite la sua interfaccia IPMI locale.", |
| 132 | + 'points': [ |
| 133 | + "Le letture avvengono sul nodo tramite il suo canale IPMI locale (/dev/ipmi0): non vengono memorizzate credenziali di rete del BMC e la rete di gestione fuori banda non viene utilizzata.", |
| 134 | + "Vengono emessi solo comandi IPMI di sola lettura (sensori, registro eventi, inventario FRU, consumo). Nessuna operazione di alimentazione, supporti virtuali o firmware.", |
| 135 | + "Se abiliti l'installazione, PegaProx installerà il pacchetto « ipmitool » e potrà caricare i moduli kernel IPMI sul nodo.", |
| 136 | + "Su sistemi fortemente irrobustiti, l'interfaccia IPMI locale può essere disattivata intenzionalmente secondo una baseline di funzionalità minima. Abilitarla qui non annulla questo — dove l'interfaccia è assente, PegaProx non restituisce dati anziché riattivarla.", |
| 137 | + ], |
| 138 | + 'compliance_note': "L'abilitazione può essere rilevante per i tuoi controlli di funzionalità minima e di irrobustimento del BMC (ad es. CMMC / NIST 800-171 3.4.6 e 3.1.5, linee guida DISA STIG BMC/OOB). Verifica con il tuo responsabile della conformità. Questo non è un parere legale.", |
| 139 | + 'confirm_label': "Comprendo e accetto la responsabilità di abilitare questa funzione", |
| 140 | + }, |
61 | 141 | } |
62 | 142 |
|
63 | 143 |
|
| 144 | +def hw_consent_warning(lang=None): |
| 145 | + """The consent warning for `lang` (falls back to English), with the shared |
| 146 | + version + delay injected so they can never drift per-language.""" |
| 147 | + base = (lang or 'en').split('-')[0].lower() |
| 148 | + text = _HW_CONSENT_TEXT.get(base) or _HW_CONSENT_TEXT['en'] |
| 149 | + return {'version': HW_CONSENT_VERSION, 'require_delay_seconds': HW_CONSENT_DELAY_SECONDS, **text} |
| 150 | + |
| 151 | + |
| 152 | +# Backward-compat English alias for callers/tests that referenced the old constant. |
| 153 | +HW_CONSENT_WARNING = hw_consent_warning('en') |
| 154 | + |
| 155 | + |
64 | 156 | def _num(s): |
65 | 157 | """First numeric token in a string as float, or None.""" |
66 | 158 | m = re.search(r'-?\d+(?:\.\d+)?', s or '') |
|
0 commit comments