mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
connect
This commit is contained in:
@@ -16,12 +16,13 @@ sync_es_users:
|
|||||||
- /opt/so/saltstack/local/salt/elasticsearch/files/users
|
- /opt/so/saltstack/local/salt/elasticsearch/files/users
|
||||||
- /opt/so/saltstack/local/salt/elasticsearch/files/users_roles
|
- /opt/so/saltstack/local/salt/elasticsearch/files/users_roles
|
||||||
- /opt/so/conf/soc/soc_users_roles
|
- /opt/so/conf/soc/soc_users_roles
|
||||||
- /opt/so/conf/soc/soc_client_roles
|
- /opt/so/conf/soc/soc_clients_roles
|
||||||
- show_changes: False
|
- show_changes: False
|
||||||
- require:
|
- require:
|
||||||
- docker_container: so-kratos
|
- docker_container: so-kratos
|
||||||
- http: wait_for_kratos
|
- http: wait_for_kratos
|
||||||
- file: so-user.lock # require so-user.lock file to be missing
|
- file: so-user.lock # require so-user.lock file to be missing
|
||||||
|
- file: so-client.lock # require so-client.lock file to be missing
|
||||||
|
|
||||||
# we dont want this added too early in setup, so we add the onlyif to verify 'startup_states: highstate'
|
# we dont want this added too early in setup, so we add the onlyif to verify 'startup_states: highstate'
|
||||||
# is in the minion config. That line is added before the final highstate during setup
|
# is in the minion config. That line is added before the final highstate during setup
|
||||||
|
|||||||
@@ -136,7 +136,7 @@ bcryptRounds=${BCRYPT_ROUNDS:-12}
|
|||||||
elasticUsersFile=${ELASTIC_USERS_FILE:-/opt/so/saltstack/local/salt/elasticsearch/files/users}
|
elasticUsersFile=${ELASTIC_USERS_FILE:-/opt/so/saltstack/local/salt/elasticsearch/files/users}
|
||||||
elasticRolesFile=${ELASTIC_ROLES_FILE:-/opt/so/saltstack/local/salt/elasticsearch/files/users_roles}
|
elasticRolesFile=${ELASTIC_ROLES_FILE:-/opt/so/saltstack/local/salt/elasticsearch/files/users_roles}
|
||||||
socRolesFile=${SOC_ROLES_FILE:-/opt/so/conf/soc/soc_users_roles}
|
socRolesFile=${SOC_ROLES_FILE:-/opt/so/conf/soc/soc_users_roles}
|
||||||
clientRolesFile=${SOC_ROLES_FILE:-/opt/so/conf/soc/soc_client_roles}
|
clientRolesFile=${SOC_ROLES_FILE:-/opt/so/conf/soc/soc_clients_roles}
|
||||||
esUID=${ELASTIC_UID:-930}
|
esUID=${ELASTIC_UID:-930}
|
||||||
esGID=${ELASTIC_GID:-930}
|
esGID=${ELASTIC_GID:-930}
|
||||||
soUID=${SOCORE_UID:-939}
|
soUID=${SOCORE_UID:-939}
|
||||||
|
|||||||
@@ -176,6 +176,12 @@ socusersroles:
|
|||||||
- require:
|
- require:
|
||||||
- sls: manager.sync_es_users
|
- sls: manager.sync_es_users
|
||||||
|
|
||||||
|
socclientsroles:
|
||||||
|
file.exists:
|
||||||
|
- name: /opt/so/conf/soc/soc_clients_roles
|
||||||
|
- require:
|
||||||
|
- sls: manager.sync_es_users
|
||||||
|
|
||||||
socuploaddir:
|
socuploaddir:
|
||||||
file.directory:
|
file.directory:
|
||||||
- name: /nsm/soc/uploads
|
- name: /nsm/soc/uploads
|
||||||
|
|||||||
@@ -1403,6 +1403,7 @@ soc:
|
|||||||
- rbac/custom_roles
|
- rbac/custom_roles
|
||||||
userFiles:
|
userFiles:
|
||||||
- rbac/users_roles
|
- rbac/users_roles
|
||||||
|
- rbac/clients_roles
|
||||||
strelkaengine:
|
strelkaengine:
|
||||||
aiRepoUrl: https://github.com/Security-Onion-Solutions/securityonion-resources
|
aiRepoUrl: https://github.com/Security-Onion-Solutions/securityonion-resources
|
||||||
aiRepoBranch: generated-summaries-published
|
aiRepoBranch: generated-summaries-published
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ so-soc:
|
|||||||
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
||||||
- /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro
|
- /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro
|
||||||
- /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw
|
- /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw
|
||||||
- /opt/so/conf/soc/soc_client_roles:/opt/sensoroni/rbac/client_roles:rw
|
- /opt/so/conf/soc/soc_clients_roles:/opt/sensoroni/rbac/clients_roles:rw
|
||||||
- /opt/so/conf/soc/queue:/opt/sensoroni/queue:rw
|
- /opt/so/conf/soc/queue:/opt/sensoroni/queue:rw
|
||||||
- /opt/so/saltstack:/opt/so/saltstack:rw
|
- /opt/so/saltstack:/opt/so/saltstack:rw
|
||||||
- /opt/so/conf/soc/migrations:/opt/so/conf/soc/migrations:rw
|
- /opt/so/conf/soc/migrations:/opt/so/conf/soc/migrations:rw
|
||||||
@@ -83,6 +83,7 @@ so-soc:
|
|||||||
- file: soccustom
|
- file: soccustom
|
||||||
- file: soccustomroles
|
- file: soccustomroles
|
||||||
- file: socusersroles
|
- file: socusersroles
|
||||||
|
- file: socclientroles
|
||||||
|
|
||||||
delete_so-soc_so-status.disabled:
|
delete_so-soc_so-status.disabled:
|
||||||
file.uncomment:
|
file.uncomment:
|
||||||
|
|||||||
Reference in New Issue
Block a user