Add standard security response headers (X-Frame-Options, X-Content-Type- Options, Content-Security-Policy, X-Permitted-Cross-Domain-Policies) to the /install and /tftpboot directories, mask the server banner with "ServerTokens Prod", and drop the Includes (SSI) and MultiViews options from those file-serving directories. Indexes on /install/postscripts, /install/post and the doc directory are left intact so directory browsing still works where xCAT relies on it. The Header directives are wrapped in <IfModule mod_headers.c> so a server whose mod_headers is not loaded still starts cleanly instead of failing on an unknown directive. On Debian/Ubuntu, where mod_headers is not enabled by default, the xCAT and xCATsn package postinst scripts run "a2enmod headers" before restarting Apache so the headers take effect there as well; on RHEL/SLES the module is loaded by default and needs no action. Recovered from the unmerged lenovobuild branch (originals7ee0c129,85c8bc09,d4d1783a), adapted: the deprecated X-XSS-Protection header and the mod_allowmethods-dependent AllowMethods directive are omitted, and the Header directives use "set" rather than "append". Co-authored-by: Jarrod Johnson <10814490+jjohnson42@users.noreply.github.com>
xCAT
xCAT is a toolkit for deployment and administration of clusters of all sizes.
The xCAT sunset was only a quick eclipse
Dear xCAT Community,
The xCAT sunset has changed course. VersatusHPC has been invited to join the xCAT Consortium, and future development will move toward direct upstream contributions coordinated with the Consortium and its existing member companies.
That matters most for Enterprise Linux 10 (EL10). EL10 support is coming to xCAT, restoring a future operating-system path for sites that still rely on xCAT. This is an important change from the previous sunset guidance, where the lack of an EL10 path was one of the strongest reasons to move away from xCAT.
The xCAT Consortium continues to recommend Confluent as the long-term successor to xCAT, and that remains the Consortium position. Users planning new cluster-management deployments should evaluate Confluent and its xCAT comparison documentation.
At the same time, xCAT is no longer sunsetted. The Consortium and participating companies will continue updating xCAT while there is community and user demand for it.
In summary:
- xCAT development is continuing upstream through the Consortium and participating companies.
- Enterprise Linux 10 support is coming.
- Confluent remains the Consortium-recommended successor and migration path.
- xCAT updates will continue while there is community and user demand.
We want to thank the xCAT Consortium and community for keeping this project moving. The sun went behind the moon for a moment, but xCAT is still here.
For more information on Confluent and how to get started, please visit the Confluent: Project Page, Documentation or Confluent vs xCAT comparison.
With thanks,
The xCAT Consortium
Documentation
xCAT Documentation is hosted on Read The Docs: https://xcat-docs.readthedocs.io
Status
| xCAT Version | Build Status |
|---|---|
| Latest (master branch) | |
| Stable (latest release) |
Looking for older versions?
Open Source License
xCAT is made available under the EPL license: https://opensource.org/licenses/eclipse-1.0.php
Developers
Want to help? Check out the developers guide!