Commit Graph

  • 199c2746f1 stop salt-minion and salt-master regardless of install type. display reinstall on console and save to logfile Josh Patterson 2026-04-24 15:24:11 -04:00
  • 8eca465ef6 uninstall elastic-agent before stopping dockers on reinstall Josh Patterson 2026-04-24 14:35:11 -04:00
  • a45e59239f Merge pull request #15826 from Security-Onion-Solutions/reyesj2-es933 Jorge Reyes 2026-04-24 13:07:48 -05:00
  • 2ad0bcab7c Merge pull request #15828 from Security-Onion-Solutions/fix/annotations Josh Patterson 2026-04-24 14:00:02 -04:00
  • 070d150420 readonly soc and kratos enabled Josh Patterson 2026-04-24 13:56:35 -04:00
  • 90ecbe90d8 allow heavynodes to run elasticsearch/cluster state reyesj2 2026-04-24 12:56:27 -05:00
  • 813fa03dc3 Merge pull request #15824 from Security-Onion-Solutions/fix/reinstall2 Josh Patterson 2026-04-24 12:22:54 -04:00
  • 02381fbbe9 stop salt-cloud , belt-and-suspenders against a broken/incomplete salt RPM Josh Patterson 2026-04-24 11:33:21 -04:00
  • 0722b681b1 redo service stop on reinstall Josh Patterson 2026-04-24 11:04:46 -04:00
  • 564815e836 redo how services are stopped during reinstall Josh Patterson 2026-04-24 10:46:29 -04:00
  • 88b30adf7f Merge pull request #15823 from Security-Onion-Solutions/reyesj2-es933 Jorge Reyes 2026-04-24 09:27:08 -05:00
  • b6acf3b522 typo reyesj2 2026-04-24 09:24:58 -05:00
  • ba55468da8 Merge pull request #15822 from Security-Onion-Solutions/jertel/wip Jason Ertel 2026-04-24 08:26:55 -04:00
  • cdd217283d numeric test description Jason Ertel 2026-04-24 08:13:36 -04:00
  • 810a582717 Merge pull request #15813 from Security-Onion-Solutions/reyesj2-es933 Jorge Reyes 2026-04-23 14:51:32 -05:00
  • a6948e8dcb Remove helpLink for influxdb in soc_global.yaml Mike Reeves 2026-04-23 13:56:41 -04:00
  • 5f35554fdc Merge pull request #15712 from Security-Onion-Solutions/soupfix Mike Reeves 2026-04-23 12:39:50 -04:00
  • ee36db4dd7 Merge pull request #15817 from Security-Onion-Solutions/feature/postgres bravo Mike Reeves 2026-04-23 11:28:24 -04:00
  • 0ecc7ae594 soup: drop --local from postgres.telegraf_users reconcile Mike Reeves 2026-04-23 11:25:44 -04:00
  • fdfca469cc prevent non-manager nodes from running elasticsearch.cluster state manually reyesj2 2026-04-23 09:53:07 -05:00
  • 5f2ec76ba8 prevent fleetnode from being able to run elasticfleet.manager state manually reyesj2 2026-04-23 09:50:45 -05:00
  • b015c8ff14 remove docker import reyesj2 2026-04-23 09:31:30 -05:00
  • 7e70870a9e remove globals import reyesj2 2026-04-23 09:25:36 -05:00
  • b7faa0e437 Merge pull request #15816 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-23 10:13:57 -04:00
  • eadad6c163 soup: bootstrap postgres pillar stubs and secret on 3.0.0 upgrade Mike Reeves 2026-04-23 10:01:38 -04:00
  • 22b32a16dd include elasticfleet.config reyesj2 2026-04-23 08:30:47 -05:00
  • 22f869734e add check for files before attempting to use file pattern to load templates reyesj2 2026-04-22 23:11:31 -05:00
  • 398bc9e4ed update kibana discardCorruptObjects version reyesj2 2026-04-22 20:38:13 -05:00
  • 72dbb69a1c fix searchnodes running elasticsearch/cluster state reyesj2 2026-04-22 20:37:48 -05:00
  • 339959d1c0 split up elasticfleet/enabled state reyesj2 2026-04-22 20:30:40 -05:00
  • fad953b2b3 Merge pull request #15812 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-22 14:31:58 -04:00
  • d5c0ec4404 so-yaml_test: cover loadYaml error paths Mike Reeves 2026-04-22 14:30:51 -04:00
  • e616b4c120 so-telegraf-cred: make executable and harden error handling Mike Reeves 2026-04-22 14:25:19 -04:00
  • 2c341e5160 Merge pull request #15810 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-22 11:13:55 -04:00
  • f240a99e22 so-telegraf-cred: thin bash wrapper around so-yaml.py Mike Reeves 2026-04-22 11:09:53 -04:00
  • 614f32c5e0 Split postgres auth from per-minion telegraf creds Mike Reeves 2026-04-22 10:55:15 -04:00
  • cd6707a566 Merge pull request #15800 from Security-Onion-Solutions/feature/vm-raid-status Josh Patterson 2026-04-22 09:42:44 -04:00
  • edd207a9d5 soup update socloud.conf Josh Patterson 2026-04-22 09:20:53 -04:00
  • 8425ac4100 Merge pull request #15808 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-21 15:48:08 -04:00
  • 724d76965f soup: update postgres backfill comment to reflect reactor removal Mike Reeves 2026-04-21 15:45:05 -04:00
  • dbf4fb66a4 Clean up postgres telegraf cred on so-minion delete Mike Reeves 2026-04-21 15:43:01 -04:00
  • 5f28e9b191 Move per-minion telegraf cred provisioning into so-minion Mike Reeves 2026-04-21 15:34:15 -04:00
  • 01bd3b6e06 Merge pull request #15807 from Security-Onion-Solutions/reyesj2-es933 Jorge Reyes 2026-04-21 14:11:04 -05:00
  • 1abfd77351 Hide telegraf password from console and close so-minion race Mike Reeves 2026-04-21 15:10:57 -04:00
  • 06a555fafb urlencode elasticsearch version reyesj2 2026-04-21 14:01:31 -05:00
  • 81c0f2b464 so-yaml.py: tolerate missing ancestors in removeKey Mike Reeves 2026-04-21 14:43:10 -04:00
  • d5dc28e526 Fan postgres telegraf cred for manager on every auth run Mike Reeves 2026-04-21 14:40:19 -04:00
  • 922fc60466 Merge pull request #15804 from Security-Onion-Solutions/feature/postgres-integration Mike Reeves 2026-04-21 11:14:56 -04:00
  • 7411031e11 Merge pull request #15803 from Security-Onion-Solutions/jertel/wip Jason Ertel 2026-04-21 10:21:56 -04:00
  • 247091766c more error handling during image updates Jason Ertel 2026-04-21 10:18:05 -04:00
  • 7f93110d68 Merge remote-tracking branch 'origin/3/dev' into feature/vm-raid-status Josh Patterson 2026-04-21 10:10:38 -04:00
  • 05f6503d61 Gate postgres telegraf fan-out on reactor-provided minion id Mike Reeves 2026-04-21 10:05:08 -04:00
  • a149ea7e8f Skip per-minion pillar fan-out when cred is already in place Mike Reeves 2026-04-21 09:59:46 -04:00
  • bb71e44614 Write per-minion telegraf creds to each minion's own pillar file Mike Reeves 2026-04-21 09:57:35 -04:00
  • 84197fb33b Move postgres backup script and cron to the postgres states Mike Reeves 2026-04-21 09:42:41 -04:00
  • 89a6e7c0dd Tidy config.sls makedirs and postgres helpLinks Mike Reeves 2026-04-21 09:39:58 -04:00
  • a902f667ba Target manager by role grain in telegraf_postgres_sync orch Mike Reeves 2026-04-21 09:37:35 -04:00
  • f72c30abd0 Have postgres.telegraf_users include postgres.enabled Mike Reeves 2026-04-21 09:35:59 -04:00
  • 37e9257698 Change so-postgres final_octet to 47 Mike Reeves 2026-04-21 09:33:47 -04:00
  • 72105f1f2f Drop telegraf push from new-minion orch; highstate covers it Mike Reeves 2026-04-21 09:31:45 -04:00
  • ee89b78751 Fire telegraf user sync on salt/key accept, not salt/auth Mike Reeves 2026-04-20 19:54:06 -04:00
  • 33ef138866 Merge pull request #15797 from Security-Onion-Solutions/jertel/wip Jason Ertel 2026-04-20 17:14:53 -04:00
  • 71da27dc8e fix template annotation Jason Ertel 2026-04-20 17:02:25 -04:00
  • 80bf07ffd8 Flesh out soc_postgres.yaml annotations Mike Reeves 2026-04-20 16:36:37 -04:00
  • b69e50542a Use TELEGRAFMERGED for telegraf.output and de-jinja pg_hba.conf Mike Reeves 2026-04-20 16:06:01 -04:00
  • 3ecd19d085 Move telegraf_output from global pillar to telegraf pillar Mike Reeves 2026-04-20 16:03:02 -04:00
  • b6a3d1889c Fix soup state.apply args for postgres provisioning Mike Reeves 2026-04-20 14:40:32 -04:00
  • 1cb34b089c Restore 3/dev soup and add postgres users to post_to_3.1.0 Mike Reeves 2026-04-20 14:38:55 -04:00
  • 1537ba5031 Merge remote-tracking branch 'origin/3/dev' into feature/postgres Mike Reeves 2026-04-20 14:32:05 -04:00
  • da69f0f1a4 Merge pull request #15793 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-20 12:38:29 -04:00
  • 8225d41661 Harden postgres secrets, TLS enforcement, and admin tooling Mike Reeves 2026-04-20 12:10:05 -04:00
  • ee437265fc monitor raid for vms Josh Patterson 2026-04-20 12:00:02 -04:00
  • affede7f0a Rename 'ScanLNK' to 'ScanLnk' in YAML config Josh Brower 2026-04-20 10:01:10 -04:00
  • 97366c0496 Rename 'ScanLNK' to 'ScanLnk' in defaults.yaml Josh Brower 2026-04-20 10:00:29 -04:00
  • 3f46caaf02 Revoke PUBLIC CONNECT on securityonion database Mike Reeves 2026-04-17 19:10:07 -04:00
  • f3181b204a Remove so-telegraf-trim and update retention description Mike Reeves 2026-04-17 19:06:16 -04:00
  • dd39db4584 Drop so_telegraf_trim cron.absent tombstone Mike Reeves 2026-04-17 18:59:39 -04:00
  • 29b24fa263 Merge pull request #15788 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-17 16:46:59 -04:00
  • 759880a800 Wait for TCP-ready postgres, not the init-phase Unix socket Mike Reeves 2026-04-17 16:43:41 -04:00
  • 981d8bb805 Merge pull request #15787 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-17 15:47:35 -04:00
  • f5cd90d139 Merge pull request #15786 from Security-Onion-Solutions/reyesj2-es933 Jorge Reyes 2026-04-17 14:47:11 -05:00
  • 31383bd9d0 Make Telegraf Postgres templates idempotent Mike Reeves 2026-04-17 15:43:50 -04:00
  • ebb93b4fa7 add wait_for_so-elasticsearch state and split elasticsearch cluster configuration out of enabled.sls reyesj2 2026-04-17 14:43:07 -05:00
  • 21076af01e Grant so_telegraf CREATE on partman schema Mike Reeves 2026-04-17 15:34:19 -04:00
  • f11e9da83a Mark time column NOT NULL before partman.create_parent Mike Reeves 2026-04-17 15:27:06 -04:00
  • 0fddcd8fe7 Pass unquoted schema.name to partman.create_parent Mike Reeves 2026-04-17 15:22:57 -04:00
  • 927eba566c Grant so_telegraf access to partman schema Mike Reeves 2026-04-17 15:13:08 -04:00
  • af9330a9dd Escape Go-template placeholders from Jinja in telegraf.conf Mike Reeves 2026-04-17 15:04:37 -04:00
  • b3fbd5c7a4 Use Go-template placeholders and shell-guarded CREATE DATABASE Mike Reeves 2026-04-17 14:55:13 -04:00
  • 4e3dbd800c Merge pull request #15785 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-17 13:03:26 -04:00
  • 5228668be0 Fix Telegraf→Postgres table creation and state.apply race Mike Reeves 2026-04-17 13:00:12 -04:00
  • dc998191d9 Merge pull request #15784 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-17 10:55:00 -04:00
  • 7d07f3c8fe Create so_telegraf DB from Salt and pin pg_partman schema Mike Reeves 2026-04-17 10:51:08 -04:00
  • e604ad5969 Update so-nsm-clear feature/so-nsm-clear bryant-treacle 2026-04-17 09:54:33 -04:00
  • 9cce920d78 Merge pull request #15781 from Security-Onion-Solutions/feature/postgres Mike Reeves 2026-04-16 17:29:29 -04:00
  • d9a9029ce5 Adopt pg_partman + pg_cron for Telegraf metric tables Mike Reeves 2026-04-16 17:27:15 -04:00
  • 9fe53d9ccc Use JSONB for Telegraf fields/tags to avoid 1600-column limit Mike Reeves 2026-04-16 17:02:21 -04:00
  • f7b80f5931 Merge branch '3/dev' into feature/postgres Mike Reeves 2026-04-16 16:37:02 -04:00
  • f11d315fea Fix soup Mike Reeves 2026-04-16 16:35:24 -04:00
  • 2013bf9e30 Fix soup Mike Reeves 2026-04-16 16:20:25 -04:00