mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-07-23 09:15:41 +02:00
Move highstate_interval_hours to salt.schedule and split schedule.sls
highstate_interval_hours describes the per-minion highstate schedule, not the active-push pipeline, so relocate it from salt.auto_apply to a new salt.schedule settings subtree. Repoint so-salt-minion-check at the new pillar path (it had been left on the stale global:push path) so its restart grace period tracks the schedule again. - Add salt.schedule.highstate_interval_hours to defaults.yaml/soc_salt.yaml and a side-effect-free salt/salt/schedule.map.jinja (SCHEDULEMERGED), matching the *MERGED map convention. Consumers read SCHEDULEMERGED.highstate_interval_hours. - Split salt/schedule.sls into salt/salt/highstate_schedule.sls (every minion) and salt/salt/push_drain_schedule.sls (managers); update top.sls to apply the highstate schedule via '*' and the drainer schedule via the configured-manager block. Remove the now-empty schedule.sls aggregator. - pillar_push_map.yaml and so-push-drainer: comment/doc updates only.
This commit is contained in:
@@ -186,12 +186,12 @@ registry:
|
||||
tgt: 'G@role:so-eval or G@role:so-import or G@role:so-manager or G@role:so-managerhype or G@role:so-managersearch or G@role:so-standalone'
|
||||
|
||||
# salt: fanout to a fleetwide highstate. The salt.auto_apply settings tune the
|
||||
# push pipeline itself (enabled, debounce/drain intervals, batch sizing) and the
|
||||
# per-minion highstate schedule; they are consumed by the manager's schedule,
|
||||
# beacons, and master reactor config as well as every minion's highstate
|
||||
# schedule, so a targeted re-apply isn't meaningful. A salt audit row only fires
|
||||
# for SOC-driven salt.auto_apply edits -- salt version bumps go through soup, not
|
||||
# SOC, so they never reach this map.
|
||||
# push pipeline itself (enabled, debounce/drain intervals, batch sizing) and
|
||||
# salt.schedule sets the per-minion highstate interval; they are consumed by the
|
||||
# manager's schedule, beacons, and master reactor config as well as every
|
||||
# minion's highstate schedule, so a targeted re-apply isn't meaningful. A salt
|
||||
# audit row only fires for SOC-driven salt.auto_apply / salt.schedule edits --
|
||||
# salt version bumps go through soup, not SOC, so they never reach this map.
|
||||
salt:
|
||||
- highstate: True
|
||||
tgt: '*'
|
||||
|
||||
Reference in New Issue
Block a user