mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-20 22:54:26 +02:00
Annotate the soauth network leaves instead of the networks map
SOC reported "Malformed config setting (docker.networks.soauth.range): Setting name 'networks' conflicts with another similarly named setting" and refused to render the config tree. soc_docker.yaml annotated docker.networks itself, and every key in that block was a scalar, so FlattenAnnotations registered docker.networks as a setting. defaults.yaml holds a nested map there, so FlattenPillar separately registered docker.networks.soauth.range, .gateway and .manager_only, and HydrateAnnotations unions the two sets. The config tree gives each id segment either a value or children, never both, so addToNode pushed docker.networks as a childless leaf and then threw when docker.networks.soauth.range tried to descend through it. The annotations move down to the three leaves that actually carry values, so docker.networks is a plain branch. This matches docker.containers, which is nested the same way and has never carried annotations of its own. docker.ulimits and the per-container networks list are unaffected: their pillar values are lists rather than maps, so they stay single settings.
This commit is contained in:
@@ -8,15 +8,32 @@ docker:
|
||||
helpLink: docker
|
||||
advanced: True
|
||||
networks:
|
||||
description: |
|
||||
Docker networks used by the grid. sobridge carries most containers and takes its range and
|
||||
gateway from the docker.range and docker.gateway settings above. soauth is an isolated
|
||||
network for the authentication services, so that the Kratos admin and Hydra API is only reachable
|
||||
from the containers placed on it.
|
||||
helpLink: docker
|
||||
readonly: True
|
||||
advanced: True
|
||||
global: True
|
||||
soauth:
|
||||
range:
|
||||
description: |
|
||||
IP range for the soauth docker network. soauth is an isolated network for the
|
||||
authentication services, so that the Kratos and Hydra admin APIs are only reachable
|
||||
from the containers placed on it. Most containers instead use sobridge, which takes
|
||||
its range and gateway from the docker.range and docker.gateway settings above.
|
||||
helpLink: docker
|
||||
readonly: True
|
||||
advanced: True
|
||||
global: True
|
||||
gateway:
|
||||
description: Gateway for the soauth docker network.
|
||||
helpLink: docker
|
||||
readonly: True
|
||||
advanced: True
|
||||
global: True
|
||||
manager_only:
|
||||
description: |
|
||||
Limits the soauth network to grid members running the authentication containers,
|
||||
instead of creating it on every node.
|
||||
helpLink: docker
|
||||
readonly: True
|
||||
advanced: True
|
||||
global: True
|
||||
forcedType: bool
|
||||
ulimits:
|
||||
description: |
|
||||
Default ulimit settings applied to all containers via the Docker daemon. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with soft and hard limits. Individual container ulimits override these defaults. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.
|
||||
|
||||
Reference in New Issue
Block a user