mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-10-08 23:35:37 +02:00
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
098699613e |
No files matched your search
@@ -29,16 +29,27 @@ install_libvirt-libs:
|
|||||||
pkg.installed:
|
pkg.installed:
|
||||||
- name: libvirt-libs
|
- name: libvirt-libs
|
||||||
|
|
||||||
|
# Root pip-installs these below, so they cannot live under /opt/so/conf (939:939 mode 770):
|
||||||
|
# write permission on that directory lets uid 939 swap the tree between this state and the
|
||||||
|
# install. /opt/saltstack is root-owned, so the same trick does not work there.
|
||||||
libvirt_python_wheel:
|
libvirt_python_wheel:
|
||||||
file.recurse:
|
file.recurse:
|
||||||
- name: /opt/so/conf/libvirt/source-packages/libvirt-python
|
- name: /opt/saltstack/source-packages/libvirt-python
|
||||||
- source: salt://libvirt/source-packages/libvirt-python
|
- source: salt://libvirt/source-packages/libvirt-python
|
||||||
|
- user: root
|
||||||
|
- group: root
|
||||||
|
- dir_mode: 755
|
||||||
|
- file_mode: 644
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
- clean: True
|
- clean: True
|
||||||
|
|
||||||
|
old_libvirt_python_wheel:
|
||||||
|
file.absent:
|
||||||
|
- name: /opt/so/conf/libvirt/source-packages
|
||||||
|
|
||||||
libvirt_python_module:
|
libvirt_python_module:
|
||||||
cmd.run:
|
cmd.run:
|
||||||
- name: /opt/saltstack/salt/bin/python3 -m pip install --no-index --find-links=/opt/so/conf/libvirt/source-packages/libvirt-python libvirt-python
|
- name: /opt/saltstack/salt/bin/python3 -m pip install --no-index --find-links=/opt/saltstack/source-packages/libvirt-python libvirt-python
|
||||||
- onchanges:
|
- onchanges:
|
||||||
- file: libvirt_python_wheel
|
- file: libvirt_python_wheel
|
||||||
|
|
||||||
|
|||||||
@@ -3,19 +3,34 @@
|
|||||||
# https://securityonion.net/license; you may not use this file except in compliance with the
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
||||||
# Elastic License 2.0.
|
# Elastic License 2.0.
|
||||||
|
|
||||||
|
# These wheels are pip-installed by root below, so they cannot live under /opt/so/conf:
|
||||||
|
# that directory is 939:939 mode 770, and write permission on it is what lets uid 939
|
||||||
|
# rename the tree aside and substitute its own wheels between this state and the install.
|
||||||
|
# Hardening only the files here would not help -- renaming an entry needs write on the
|
||||||
|
# parent, not on the entry.
|
||||||
docker_module_package:
|
docker_module_package:
|
||||||
file.recurse:
|
file.recurse:
|
||||||
- name: /opt/so/conf/salt/module_packages/docker
|
- name: /opt/saltstack/module_packages/docker
|
||||||
- source: salt://salt/module_packages/docker
|
- source: salt://salt/module_packages/docker
|
||||||
|
- user: root
|
||||||
|
- group: root
|
||||||
|
- dir_mode: 755
|
||||||
|
- file_mode: 644
|
||||||
- clean: True
|
- clean: True
|
||||||
- makedirs: True
|
- makedirs: True
|
||||||
|
|
||||||
|
# Installs before this change left wheels in a socore-writable directory; nothing reads
|
||||||
|
# them now, but leaving them behind leaves a writable staging area lying around.
|
||||||
|
old_docker_module_package:
|
||||||
|
file.absent:
|
||||||
|
- name: /opt/so/conf/salt/module_packages
|
||||||
|
|
||||||
# fail hard on this state so that soup would be cancelled on a manager (eventhough salt would have already updated)
|
# fail hard on this state so that soup would be cancelled on a manager (eventhough salt would have already updated)
|
||||||
# on a non manager, failing hard here will prevent the minion from upgrading
|
# on a non manager, failing hard here will prevent the minion from upgrading
|
||||||
# we want to fail hard here to prevent the minion from upgrading and potetially being able to manager docker containers from a dep mismatch
|
# we want to fail hard here to prevent the minion from upgrading and potetially being able to manager docker containers from a dep mismatch
|
||||||
docker_python_module_install:
|
docker_python_module_install:
|
||||||
cmd.run:
|
cmd.run:
|
||||||
- name: /opt/saltstack/salt/bin/python3.10 -m pip install docker --no-index --find-links=/opt/so/conf/salt/module_packages/docker/ --upgrade
|
- name: /opt/saltstack/salt/bin/python3.10 -m pip install docker --no-index --find-links=/opt/saltstack/module_packages/docker/ --upgrade
|
||||||
- onchanges:
|
- onchanges:
|
||||||
- file: docker_module_package
|
- file: docker_module_package
|
||||||
- failhard: True
|
- failhard: True
|
||||||
Reference in new issue
Block a user