mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-07-28 03:33:28 +02:00
salt.schedule.highstate_interval_hours could not express a sub-hour cadence, so an operator who disables salt.auto_apply had no way back to the legacy 15-minute highstate. Rename the setting to highstate_interval_minutes (default 120, behavior unchanged) and enforce a 15-minute floor in SOC. Non-manager splay is now a quarter of the interval clamped to [5, 30] minutes, so a short interval no longer gets jitter larger than itself; at the 120-minute default it stays 1800s. The so-salt-minion-check restart threshold keeps its interval-plus-one-hour grace, now in minute math.
42 lines
2.2 KiB
YAML
42 lines
2.2 KiB
YAML
salt:
|
|
auto_apply:
|
|
enabled:
|
|
description: Master kill-switch for the active push feature. When disabled, rule and pillar changes are picked up at the next scheduled highstate instead of being pushed immediately.
|
|
forcedType: bool
|
|
helpLink: push
|
|
global: True
|
|
debounce_seconds:
|
|
description: Trailing-edge debounce window in seconds. A push intent must be quiet for this long before the drainer dispatches. Rapid bursts of edits within this window coalesce into one dispatch.
|
|
forcedType: int
|
|
helpLink: push
|
|
global: True
|
|
advanced: True
|
|
drain_interval:
|
|
description: How often the push drainer checks for ready intents, in seconds. Small values lower dispatch latency at the cost of more background work on the manager.
|
|
forcedType: int
|
|
helpLink: push
|
|
global: True
|
|
advanced: True
|
|
batch:
|
|
description: "Host batch size for push orchestrations. A number (e.g. '10') or a percentage (e.g. '25%'). Limits how many minions run the push state at once so large fleets don't thundering-herd."
|
|
helpLink: push
|
|
global: True
|
|
advanced: True
|
|
regex: '^([0-9]+%?)$'
|
|
regexFailureMessage: Enter a whole number or a whole-number percentage (e.g. 10 or 25%).
|
|
batch_wait:
|
|
description: Seconds to wait between host batches in a push orchestration. Gives the fleet time to breathe between waves.
|
|
forcedType: int
|
|
helpLink: push
|
|
global: True
|
|
advanced: True
|
|
schedule:
|
|
highstate_interval_minutes:
|
|
description: How often every minion in the grid runs a scheduled state.highstate, in minutes. Minimum 15 minutes. Lower values keep minions closer in sync at the cost of more load; higher values reduce load but increase worst-case latency for non-pushed changes. If Auto Apply is disabled, set this to the 15-minute minimum so changes are still picked up promptly. The salt-minion health check restarts a minion if its last state apply is older than this value plus one hour.
|
|
forcedType: int
|
|
helpLink: push
|
|
global: True
|
|
advanced: True
|
|
regex: '^(1[5-9]|[2-9][0-9]|[1-9][0-9]{2,4})$'
|
|
regexFailureMessage: The value must be an integer of at least 15 minutes (maximum 99999).
|