mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
require files before starting soc or kratos
This commit is contained in:
@@ -80,6 +80,10 @@ soccustomroles:
|
|||||||
- mode: 600
|
- mode: 600
|
||||||
- template: jinja
|
- template: jinja
|
||||||
|
|
||||||
|
socusersroles:
|
||||||
|
file.exists:
|
||||||
|
- name: /opt/so/conf/soc/soc_users_roles
|
||||||
|
|
||||||
# we dont want this added too early in setup, so we add the onlyif to verify 'startup_states: highstate'
|
# we dont want this added too early in setup, so we add the onlyif to verify 'startup_states: highstate'
|
||||||
# is in the minion config. That line is added before the final highstate during setup
|
# is in the minion config. That line is added before the final highstate during setup
|
||||||
sosyncusers:
|
sosyncusers:
|
||||||
@@ -95,13 +99,13 @@ so-soc:
|
|||||||
- name: so-soc
|
- name: so-soc
|
||||||
- binds:
|
- binds:
|
||||||
- /nsm/soc/jobs:/opt/sensoroni/jobs:rw
|
- /nsm/soc/jobs:/opt/sensoroni/jobs:rw
|
||||||
|
- /opt/so/log/soc/:/opt/sensoroni/logs/:rw
|
||||||
- /opt/so/conf/soc/soc.json:/opt/sensoroni/sensoroni.json:ro
|
- /opt/so/conf/soc/soc.json:/opt/sensoroni/sensoroni.json:ro
|
||||||
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
- /opt/so/conf/soc/motd.md:/opt/sensoroni/html/motd.md:ro
|
||||||
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
- /opt/so/conf/soc/banner.md:/opt/sensoroni/html/login/banner.md:ro
|
||||||
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
- /opt/so/conf/soc/custom.js:/opt/sensoroni/html/js/custom.js:ro
|
||||||
- /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro
|
- /opt/so/conf/soc/custom_roles:/opt/sensoroni/rbac/custom_roles:ro
|
||||||
- /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw
|
- /opt/so/conf/soc/soc_users_roles:/opt/sensoroni/rbac/users_roles:rw
|
||||||
- /opt/so/log/soc/:/opt/sensoroni/logs/:rw
|
|
||||||
{%- if salt['pillar.get']('nodestab', {}) %}
|
{%- if salt['pillar.get']('nodestab', {}) %}
|
||||||
- extra_hosts:
|
- extra_hosts:
|
||||||
{%- for SN, SNDATA in salt['pillar.get']('nodestab', {}).items() %}
|
{%- for SN, SNDATA in salt['pillar.get']('nodestab', {}).items() %}
|
||||||
@@ -112,6 +116,15 @@ so-soc:
|
|||||||
- 0.0.0.0:9822:9822
|
- 0.0.0.0:9822:9822
|
||||||
- watch:
|
- watch:
|
||||||
- file: /opt/so/conf/soc/*
|
- file: /opt/so/conf/soc/*
|
||||||
|
- require:
|
||||||
|
- file: socdatadir
|
||||||
|
- file: soclogdir
|
||||||
|
- file: socconfig
|
||||||
|
- file: socmotd
|
||||||
|
- file: socbanner
|
||||||
|
- file: soccustom
|
||||||
|
- file: soccustomroles
|
||||||
|
- file: socusersroles
|
||||||
|
|
||||||
append_so-soc_so-status.conf:
|
append_so-soc_so-status.conf:
|
||||||
file.append:
|
file.append:
|
||||||
@@ -154,6 +167,14 @@ kratossync:
|
|||||||
- file_mode: 600
|
- file_mode: 600
|
||||||
- template: jinja
|
- template: jinja
|
||||||
|
|
||||||
|
kratos_schema:
|
||||||
|
file.exists:
|
||||||
|
- name: /opt/so/conf/kratos/schema.json
|
||||||
|
|
||||||
|
kratos_yaml:
|
||||||
|
file.exists:
|
||||||
|
- name: /opt/so/conf/kratos/kratos.yaml
|
||||||
|
|
||||||
so-kratos:
|
so-kratos:
|
||||||
docker_container.running:
|
docker_container.running:
|
||||||
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-kratos:{{ VERSION }}
|
- image: {{ MANAGER }}:5000/{{ IMAGEREPO }}/so-kratos:{{ VERSION }}
|
||||||
@@ -169,6 +190,11 @@ so-kratos:
|
|||||||
- 0.0.0.0:4434:4434
|
- 0.0.0.0:4434:4434
|
||||||
- watch:
|
- watch:
|
||||||
- file: /opt/so/conf/kratos
|
- file: /opt/so/conf/kratos
|
||||||
|
- require:
|
||||||
|
- file: kratos_schema
|
||||||
|
- file: kratos_yaml
|
||||||
|
- file: kratoslogdir
|
||||||
|
- file: kratosdir
|
||||||
|
|
||||||
append_so-kratos_so-status.conf:
|
append_so-kratos_so-status.conf:
|
||||||
file.append:
|
file.append:
|
||||||
|
|||||||
Reference in New Issue
Block a user