mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-18 21:59:23 +02:00
/opt/so/saltstack/default holds the source for every root-executed script -- /usr/sbin, the reactors, _runners/_modules/_beacons, the master engines and salt-relay.sh -- plus every state the root master renders. SOC mounts /opt/so/saltstack rw as uid 939, so root-owning /usr/sbin alone was not enough: the next highstate would copy attacker-controlled bytes out of the tree into the root-owned destination and run them. SOC never writes under default/, it only reads it. Every SOC write targets local/, which stays socore-owned, as does /opt/so/state. No mode is enforced on default/ -- SOC reads that tree, and 750/640 would break its config load. Also stops copy_new_files(), so-saltstack-update and setup from chowning the tree back to socore, and replaces preserve: True in soup_scripts.sls, which carried uid/gid in from the /tmp staging tree and would have undone the ownership before the first post-soup highstate.
52 lines
1.8 KiB
YAML+Jinja
52 lines
1.8 KiB
YAML+Jinja
# Copyright Security Onion Solutions LLC and/or licensed to Security Onion Solutions LLC under one
|
|
# or more contributor license agreements. Licensed under the Elastic License 2.0 as shown at
|
|
# https://securityonion.net/license; you may not use this file except in compliance with the
|
|
# Elastic License 2.0.
|
|
#
|
|
# Note: Per the Elastic License 2.0, the second limitation states:
|
|
#
|
|
# "You may not move, change, disable, or circumvent the license key functionality
|
|
# in the software, and you may not remove or obscure any functionality in the
|
|
# software that is protected by the license key."
|
|
|
|
{% if 'vrt' in salt['pillar.get']('features', []) %}
|
|
|
|
{% from 'hypervisor/map.jinja' import HYPERVISORS %}
|
|
|
|
hypervisor_annotation:
|
|
file.managed:
|
|
- name: /opt/so/saltstack/default/salt/hypervisor/soc_hypervisor.yaml
|
|
- source: salt://soc/dyanno/hypervisor/soc_hypervisor.yaml.jinja
|
|
- template: jinja
|
|
- user: root
|
|
- group: root
|
|
- defaults:
|
|
HYPERVISORS: {{ HYPERVISORS }}
|
|
baseDomainStatus: {{ salt['pillar.get']('baseDomain:status', 'Initialized') }}
|
|
|
|
{% for role in HYPERVISORS %}
|
|
{% for hypervisor in HYPERVISORS[role].keys() %}
|
|
hypervisor_host_directory_{{hypervisor}}:
|
|
file.directory:
|
|
- name: /opt/so/saltstack/local/salt/hypervisor/hosts/{{hypervisor}}
|
|
- makedirs: True
|
|
- user: socore
|
|
- group: socore
|
|
- recurse:
|
|
- user
|
|
- group
|
|
{% endfor %}
|
|
{% endfor %}
|
|
|
|
{% else %}
|
|
|
|
{{sls}}_no_license_detected:
|
|
test.fail_without_changes:
|
|
- name: {{sls}}_no_license_detected
|
|
- comment:
|
|
- "Hypervisor nodes are a feature supported only for customers with a valid license.
|
|
Contact Security Onion Solutions, LLC via our website at https://securityonionsolutions.com
|
|
for more information about purchasing a license to enable this feature."
|
|
|
|
{% endif %}
|