mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-07 09:42:46 +01:00
remove checkmine engine. add x509.get_pem_entries to managers mine_functions. simplify mine update during soup
This commit is contained in:
@@ -580,7 +580,7 @@ update_centos_repo() {
|
|||||||
update_salt_mine() {
|
update_salt_mine() {
|
||||||
echo "Populating the mine with network.ip_addrs pillar.host.mainint for each host."
|
echo "Populating the mine with network.ip_addrs pillar.host.mainint for each host."
|
||||||
set +e
|
set +e
|
||||||
salt \* cmd.run cmd='MAININT=$(salt-call pillar.get host:mainint --out=newline_values_only) && salt-call mine.send name=network.ip_addrs interface="$MAININT"'
|
salt \* mine.update
|
||||||
set -e
|
set -e
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -2,3 +2,7 @@ mine_interval: 35
|
|||||||
mine_functions:
|
mine_functions:
|
||||||
network.ip_addrs:
|
network.ip_addrs:
|
||||||
- interface: {{ GLOBALS.main_interface }}
|
- interface: {{ GLOBALS.main_interface }}
|
||||||
|
{% if GLOBALS.is_manager -%}
|
||||||
|
x509.get_pem_entries:
|
||||||
|
- glob_path: '/etc/pki/ca.crt'
|
||||||
|
{% endif -%}
|
||||||
|
|||||||
@@ -18,17 +18,14 @@ salt_master_service:
|
|||||||
- enable: True
|
- enable: True
|
||||||
|
|
||||||
checkmine_engine:
|
checkmine_engine:
|
||||||
file.managed:
|
file.absent:
|
||||||
- name: /etc/salt/engines/checkmine.py
|
- name: /etc/salt/engines/checkmine.py
|
||||||
- source: salt://salt/engines/checkmine.py
|
|
||||||
- makedirs: True
|
|
||||||
- watch_in:
|
- watch_in:
|
||||||
- service: salt_minion_service
|
- service: salt_minion_service
|
||||||
|
|
||||||
engines_config:
|
engines_config:
|
||||||
file.managed:
|
file.absent:
|
||||||
- name: /etc/salt/minion.d/engines.conf
|
- name: /etc/salt/minion.d/engines.conf
|
||||||
- source: salt://salt/files/engines.conf
|
|
||||||
- watch_in:
|
- watch_in:
|
||||||
- service: salt_minion_service
|
- service: salt_minion_service
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user