ensure /etc/pki is created and simplify ca logic for non manager in ssl state

This commit is contained in:
m0duspwnens
2021-12-28 10:41:57 -05:00
parent 0072ae253b
commit f2adcf4ca5
3 changed files with 14 additions and 17 deletions

View File

@@ -1,17 +1,14 @@
{% from 'allowed_states.map.jinja' import allowed_states %}
{% if sls in allowed_states %}
include:
- ca.dirs
{% set manager = salt['grains.get']('master') %}
/etc/salt/minion.d/signing_policies.conf:
file.managed:
- source: salt://ca/files/signing_policies.conf
/etc/pki:
file.directory: []
/etc/pki/issued_certs:
file.directory: []
pki_private_key:
x509.private_key_managed:
- name: /etc/pki/ca.key