mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-07-30 12:43:27 +02:00
salt.schedule.highstate_interval_hours could not express a sub-hour cadence, so an operator who disables salt.auto_apply had no way back to the legacy 15-minute highstate. Rename the setting to highstate_interval_minutes (default 120, behavior unchanged) and enforce a 15-minute floor in SOC. Non-manager splay is now a quarter of the interval clamped to [5, 30] minutes, so a short interval no longer gets jitter larger than itself; at the 120-minute default it stays 1800s. The so-salt-minion-check restart threshold keeps its interval-plus-one-hour grace, now in minute math.
16 lines
579 B
YAML+Jinja
16 lines
579 B
YAML+Jinja
{% from 'vars/globals.map.jinja' import GLOBALS %}
|
|
{% from 'salt/schedule.map.jinja' import SCHEDULEMERGED %}
|
|
|
|
{# splay a quarter of the interval, clamped to [5 min, 30 min], so short intervals
|
|
don't get jitter larger than the interval itself #}
|
|
{% set SPLAY = [[(SCHEDULEMERGED.highstate_interval_minutes * 60 // 4) | int, 300] | max, 1800] | min %}
|
|
|
|
highstate_schedule:
|
|
schedule.present:
|
|
- function: state.highstate
|
|
- minutes: {{ SCHEDULEMERGED.highstate_interval_minutes }}
|
|
- maxrunning: 1
|
|
{% if not GLOBALS.is_manager %}
|
|
- splay: {{ SPLAY }}
|
|
{% endif %}
|