handle steno ca certs directory properly

This commit is contained in:
Josh Patterson
2025-12-12 19:07:00 -05:00
parent a2196085d5
commit 9878d9d37e
3 changed files with 5 additions and 2 deletions

View File

@@ -25,7 +25,6 @@
{% set manager_states = [ {% set manager_states = [
'salt.master', 'salt.master',
'ca.server', 'ca.server',
'pcap.ca',
'registry', 'registry',
'manager', 'manager',
'nginx', 'nginx',

View File

@@ -177,7 +177,7 @@ so-status_script:
- source: salt://common/tools/sbin/so-status - source: salt://common/tools/sbin/so-status
- mode: 755 - mode: 755
{% if GLOBALS.role in GLOBALS.sensor_roles %} {% if GLOBALS.is_sensor %}
# Add sensor cleanup # Add sensor cleanup
so-sensor-clean: so-sensor-clean:
cron.present: cron.present:

View File

@@ -8,7 +8,9 @@
include: include:
{% if GLOBALS.is_sensor or GLOBALS.role == 'so-import' %}
- pcap.ca - pcap.ca
{% endif %}
- sensoroni.config - sensoroni.config
- sensoroni.sostatus - sensoroni.sostatus
@@ -17,7 +19,9 @@ so-sensoroni:
- image: {{ GLOBALS.registry_host }}:5000/{{ GLOBALS.image_repo }}/so-soc:{{ GLOBALS.so_version }} - image: {{ GLOBALS.registry_host }}:5000/{{ GLOBALS.image_repo }}/so-soc:{{ GLOBALS.so_version }}
- network_mode: host - network_mode: host
- binds: - binds:
{% if GLOBALS.is_sensor or GLOBALS.role == 'so-import' %}
- /opt/so/conf/steno/certs:/etc/stenographer/certs:rw - /opt/so/conf/steno/certs:/etc/stenographer/certs:rw
{% endif %}
- /nsm/pcap:/nsm/pcap:rw - /nsm/pcap:/nsm/pcap:rw
- /nsm/import:/nsm/import:rw - /nsm/import:/nsm/import:rw
- /nsm/pcapout:/nsm/pcapout:rw - /nsm/pcapout:/nsm/pcapout:rw