Looking at umask on a non-hardened unit:
ubuntu@juju-da8cbf-zaza-41517351cce1-24:~$ umask 0002 ubuntu@juju-da8cbf-zaza-41517351cce1-24:~$ touch /tmp/hello ubuntu@juju-da8cbf-zaza-41517351cce1-24:~$ ls -al /tmp/hello -rw-rw-r-- 1 ubuntu ubuntu 0 Aug 31 17:20 /tmp/hello
And on a hardened compute node:
ubuntu@juju-da8cbf-zaza-41517351cce1-26:~$ umask 0027 ubuntu@juju-da8cbf-zaza-41517351cce1-26:~$ touch /tmp/hello ubuntu@juju-da8cbf-zaza-41517351cce1-26:~$ ls -al /tmp/hello -rw-r----- 1 ubuntu ubuntu 0 Aug 31 17:20 /tmp/hello
Looking at umask on a non-hardened unit:
ubuntu@ juju-da8cbf- zaza-41517351cc e1-24:~ $ umask juju-da8cbf- zaza-41517351cc e1-24:~ $ touch /tmp/hello juju-da8cbf- zaza-41517351cc e1-24:~ $ ls -al /tmp/hello
0002
ubuntu@
ubuntu@
-rw-rw-r-- 1 ubuntu ubuntu 0 Aug 31 17:20 /tmp/hello
And on a hardened compute node:
ubuntu@ juju-da8cbf- zaza-41517351cc e1-26:~ $ umask juju-da8cbf- zaza-41517351cc e1-26:~ $ touch /tmp/hello juju-da8cbf- zaza-41517351cc e1-26:~ $ ls -al /tmp/hello
0027
ubuntu@
ubuntu@
-rw-r----- 1 ubuntu ubuntu 0 Aug 31 17:20 /tmp/hello