mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
Add cross cluster for SSL
This commit is contained in:
@@ -109,6 +109,25 @@ pillar_changes() {
|
|||||||
sed -i "/^global:/a \\ hiveplaysecret: $HIVEPLAYSECRET" /opt/so/saltstack/local/pillar/global.sls;
|
sed -i "/^global:/a \\ hiveplaysecret: $HIVEPLAYSECRET" /opt/so/saltstack/local/pillar/global.sls;
|
||||||
sed -i "/^global:/a \\ cortexplaysecret: $CORTEXPLAYSECRET" /opt/so/saltstack/local/pillar/global.sls;
|
sed -i "/^global:/a \\ cortexplaysecret: $CORTEXPLAYSECRET" /opt/so/saltstack/local/pillar/global.sls;
|
||||||
|
|
||||||
|
# Move storage nodes to hostname for SSL
|
||||||
|
# Get a list we can use:
|
||||||
|
grep -A1 searchnode /opt/so/saltstack/local/pillar/data/nodestab.sls | grep -v '\-\-' | sed '$!N;s/\n/ /' | awk '{print $1,$3}' | awk '/_searchnode:/{gsub(/\_searchnode:/, "_searchnode"); print}' >/tmp/nodes.txt
|
||||||
|
# Remove the nodes from cluster settings
|
||||||
|
while read p; do
|
||||||
|
local NAME=$(echo $p | awk '{print $1}')
|
||||||
|
local IP=$(echo $p | awk '{print $2}')
|
||||||
|
echo "Removing the old cross cluster config for $NAME"
|
||||||
|
curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/_cluster/settings -d '{"persistent":{"cluster":{"remote":{"'$NAME'":{"skip_unavailable":null,"seeds":null}}}}}'
|
||||||
|
done </tmp/nodes.txt
|
||||||
|
# Add the nodes back using hostname
|
||||||
|
while read p; do
|
||||||
|
local NAME=$(echo $p | awk '{print $1}')
|
||||||
|
local EHOSTNAME=$(echo $p | awk -F"_" '{print $1}')
|
||||||
|
echo "Adding the new cross cluster config for $NAME"
|
||||||
|
curl -XPUT http://localhost:9200/_cluster/settings -H'Content-Type: application/json' -d '{"persistent": {"search": {"remote": {"$NAME": {"skip_unavailable": "true", "seeds": ["$EHOSTNAME:9300"]}}}}}'
|
||||||
|
done </tmp/nodes.txt
|
||||||
|
|
||||||
|
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user