mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-21 15:14:27 +02:00
SOC reported "Malformed config setting (docker.networks.soauth.range): Setting name 'networks' conflicts with another similarly named setting" and refused to render the config tree. soc_docker.yaml annotated docker.networks itself, and every key in that block was a scalar, so FlattenAnnotations registered docker.networks as a setting. defaults.yaml holds a nested map there, so FlattenPillar separately registered docker.networks.soauth.range, .gateway and .manager_only, and HydrateAnnotations unions the two sets. The config tree gives each id segment either a value or children, never both, so addToNode pushed docker.networks as a childless leaf and then threw when docker.networks.soauth.range tried to descend through it. The annotations move down to the three leaves that actually carry values, so docker.networks is a plain branch. This matches docker.containers, which is nested the same way and has never carried annotations of its own. docker.ulimits and the per-container networks list are unaffected: their pillar values are lists rather than maps, so they stay single settings.
143 lines
5.3 KiB
YAML
143 lines
5.3 KiB
YAML
docker:
|
|
gateway:
|
|
description: Gateway for the default docker interface.
|
|
helpLink: docker
|
|
advanced: True
|
|
range:
|
|
description: Default docker IP range for containers.
|
|
helpLink: docker
|
|
advanced: True
|
|
networks:
|
|
soauth:
|
|
range:
|
|
description: |
|
|
IP range for the soauth docker network. soauth is an isolated network for the
|
|
authentication services, so that the Kratos and Hydra admin APIs are only reachable
|
|
from the containers placed on it. Most containers instead use sobridge, which takes
|
|
its range and gateway from the docker.range and docker.gateway settings above.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
gateway:
|
|
description: Gateway for the soauth docker network.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
manager_only:
|
|
description: |
|
|
Limits the soauth network to grid members running the authentication containers,
|
|
instead of creating it on every node.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
forcedType: bool
|
|
ulimits:
|
|
description: |
|
|
Default ulimit settings applied to all containers via the Docker daemon. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with soft and hard limits. Individual container ulimits override these defaults. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.
|
|
forcedType: "[]{}"
|
|
syntax: json
|
|
advanced: True
|
|
helpLink: docker.html
|
|
uiElements:
|
|
- field: name
|
|
label: Resource Name
|
|
required: True
|
|
regex: ^(cpu|fsize|data|stack|core|rss|nproc|nofile|memlock|as|locks|sigpending|msgqueue|nice|rtprio|rttime)$
|
|
regexFailureMessage: You must enter a valid ulimit name (cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime).
|
|
- field: soft
|
|
label: Soft Limit
|
|
forcedType: int
|
|
- field: hard
|
|
label: Hard Limit
|
|
forcedType: int
|
|
containers:
|
|
so-dockerregistry: &dockerOptions
|
|
final_octet:
|
|
description: Last octet of the container IP address.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
networks:
|
|
description: |
|
|
Docker networks this container is attached to. The first entry is the container's
|
|
primary network and determines the address its published ports are forwarded to.
|
|
Defaults to sobridge when unset.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
forcedType: "[]string"
|
|
port_bindings:
|
|
description: List of port bindings for the container.
|
|
helpLink: docker
|
|
advanced: True
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
custom_bind_mounts:
|
|
description: List of custom local volume bindings.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
extra_hosts:
|
|
description: List of additional host entries for the container.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
extra_env:
|
|
description: List of additional ENV entries for the container.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
ulimits:
|
|
description: |
|
|
Ulimit settings for the container. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with optional soft and hard limits. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.
|
|
advanced: True
|
|
helpLink: docker.html
|
|
forcedType: "[]{}"
|
|
syntax: json
|
|
uiElements:
|
|
- field: name
|
|
label: Resource Name
|
|
required: True
|
|
regex: ^(cpu|fsize|data|stack|core|rss|nproc|nofile|memlock|as|locks|sigpending|msgqueue|nice|rtprio|rttime)$
|
|
regexFailureMessage: You must enter a valid ulimit name (cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime).
|
|
- field: soft
|
|
label: Soft Limit
|
|
forcedType: int
|
|
- field: hard
|
|
label: Hard Limit
|
|
forcedType: int
|
|
so-elastic-fleet: *dockerOptions
|
|
so-elasticsearch: *dockerOptions
|
|
so-influxdb: *dockerOptions
|
|
so-kibana: *dockerOptions
|
|
so-kratos: *dockerOptions
|
|
so-hydra: *dockerOptions
|
|
so-logstash: *dockerOptions
|
|
so-nginx: *dockerOptions
|
|
so-nginx-fleet-node: *dockerOptions
|
|
so-redis: *dockerOptions
|
|
so-sensoroni: *dockerOptions
|
|
so-soc: *dockerOptions
|
|
so-strelka-backend: *dockerOptions
|
|
so-strelka-filestream: *dockerOptions
|
|
so-strelka-frontend: *dockerOptions
|
|
so-strelka-manager: *dockerOptions
|
|
so-strelka-gatekeeper: *dockerOptions
|
|
so-strelka-coordinator: *dockerOptions
|
|
so-elastalert: *dockerOptions
|
|
so-elastic-fleet-package-registry: *dockerOptions
|
|
so-idh: *dockerOptions
|
|
so-elastic-agent: *dockerOptions
|
|
so-telegraf: *dockerOptions
|
|
so-suricata: *dockerOptions
|
|
so-zeek: *dockerOptions
|
|
so-kafka: *dockerOptions
|