f3f570995e
- Update to version 3004, see release notes: https://docs.saltproject.io/en/master/topics/releases/3004.html - Don't check for cached pillar errors on state.apply (bsc#1190781) - Added: * state.apply-don-t-check-for-cached-pillar-errors.patch - Modified: * add-migrated-state-and-gpg-key-management-functions-.patch * switch-firewalld-state-to-use-change_interface.patch * include-aliases-in-the-fqdns-grains.patch * debian-info_installed-compatibility-50453.patch * info_installed-works-without-status-attr-now.patch * fix-traceback.print_exc-calls-for-test_pip_state-432.patch * add-custom-suse-capabilities-as-grains.patch * add-rpm_vercmp-python-library-for-version-comparison.patch * 3003.3-do-not-consider-skipped-targets-as-failed-for.patch * support-transactional-systems-microos.patch * do-not-crash-when-unexpected-cmd-output-at-listing-p.patch * enable-passing-a-unix_socket-for-mysql-returners-bsc.patch * update-target-fix-for-salt-ssh-to-process-targets-li.patch * fix-exception-in-yumpkg.remove-for-not-installed-pac.patch * enhance-openscap-module-add-xccdf_eval-call-386.patch * add-environment-variable-to-know-if-yum-is-invoked-f.patch * zypperpkg-ignore-retcode-104-for-search-bsc-1176697-.patch * run-salt-master-as-dedicated-salt-user.patch * 3003.3-postgresql-json-support-in-pillar-423.patch * prevent-pkg-plugins-errors-on-missing-cookie-path-bs.patch * early-feature-support-config.patch * implementation-of-held-unheld-functions-for-state-pk.patch * x509-fixes-111.patch * fix-issues-with-salt-ssh-s-extra-filerefs.patch * mock-ip_addrs-in-utils-minions.py-unit-test-443.patch OBS-URL: https://build.opensuse.org/request/show/949489 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/salt?expand=0&rev=123 |
||
---|---|---|
_lastrevision | ||
_service | ||
.gitattributes | ||
.gitignore | ||
3003.3-do-not-consider-skipped-targets-as-failed-for.patch | ||
3003.3-postgresql-json-support-in-pillar-423.patch | ||
activate-all-beacons-sources-config-pillar-grains.patch | ||
add-custom-suse-capabilities-as-grains.patch | ||
add-environment-variable-to-know-if-yum-is-invoked-f.patch | ||
add-migrated-state-and-gpg-key-management-functions-.patch | ||
add-publish_batch-to-clearfuncs-exposed-methods.patch | ||
add-rpm_vercmp-python-library-for-version-comparison.patch | ||
add-sleep-on-exception-handling-on-minion-connection.patch | ||
add-standalone-configuration-file-for-enabling-packa.patch | ||
adds-explicit-type-cast-for-port.patch | ||
allow-vendor-change-option-with-zypper.patch | ||
async-batch-implementation.patch | ||
avoid-excessive-syslogging-by-watchdog-cronjob-58.patch | ||
batch.py-avoid-exception-when-minion-does-not-respon.patch | ||
bsc-1176024-fix-file-directory-user-and-group-owners.patch | ||
check-if-dpkgnotify-is-executable-bsc-1186674-376.patch | ||
debian-info_installed-compatibility-50453.patch | ||
dnfnotify-pkgset-plugin-implementation-3002.2-450.patch | ||
do-not-crash-when-unexpected-cmd-output-at-listing-p.patch | ||
do-not-load-pip-state-if-there-is-no-3rd-party-depen.patch | ||
don-t-use-shell-sbin-nologin-in-requisites.patch | ||
early-feature-support-config.patch | ||
enable-passing-a-unix_socket-for-mysql-returners-bsc.patch | ||
enhance-logging-when-inotify-beacon-is-missing-pyino.patch | ||
enhance-openscap-module-add-xccdf_eval-call-386.patch | ||
fix-bsc-1065792.patch | ||
fix-crash-when-calling-manage.not_alive-runners.patch | ||
fix-exception-in-yumpkg.remove-for-not-installed-pac.patch | ||
fix-for-suse-expanded-support-detection.patch | ||
fix-ip6_interface-grain-to-not-leak-secondary-ipv4-a.patch | ||
fix-issue-2068-test.patch | ||
fix-issues-with-salt-ssh-s-extra-filerefs.patch | ||
fix-missing-minion-returns-in-batch-mode-360.patch | ||
fix-salt.utils.stringutils.to_str-calls-to-make-it-w.patch | ||
fix-the-regression-for-yumnotify-plugin-456.patch | ||
fix-traceback.print_exc-calls-for-test_pip_state-432.patch | ||
fix-wrong-test_mod_del_repo_multiline_values-test-af.patch | ||
fixes-56144-to-enable-hotadd-profile-support.patch | ||
force-zyppnotify-to-prefer-packages.db-than-packages.patch | ||
html.tar.bz2 | ||
implementation-of-held-unheld-functions-for-state-pk.patch | ||
implementation-of-suse_ip-execution-module-bsc-10999.patch | ||
improvements-on-ansiblegate-module-354.patch | ||
include-aliases-in-the-fqdns-grains.patch | ||
info_installed-works-without-status-attr-now.patch | ||
let-salt-ssh-use-platform-python-binary-in-rhel8-191.patch | ||
make-aptpkg.list_repos-compatible-on-enabled-disable.patch | ||
make-setup.py-script-to-not-require-setuptools-9.1.patch | ||
mock-ip_addrs-in-utils-minions.py-unit-test-443.patch | ||
notify-beacon-for-debian-ubuntu-systems-347.patch | ||
prevent-pkg-plugins-errors-on-missing-cookie-path-bs.patch | ||
read-repo-info-without-using-interpolation-bsc-11356.patch | ||
README.SUSE | ||
refactor-and-improvements-for-transactional-updates-.patch | ||
restore-default-behaviour-of-pkg-list-return.patch | ||
return-the-expected-powerpc-os-arch-bsc-1117995.patch | ||
revert-fixing-a-use-case-when-multiple-inotify-beaco.patch | ||
run-salt-api-as-user-salt-bsc-1064520.patch | ||
run-salt-master-as-dedicated-salt-user.patch | ||
salt-tmpfiles.d | ||
salt.changes | ||
salt.spec | ||
state.apply-don-t-check-for-cached-pillar-errors.patch | ||
support-transactional-systems-microos.patch | ||
switch-firewalld-state-to-use-change_interface.patch | ||
temporary-fix-extend-the-whitelist-of-allowed-comman.patch | ||
transactional_update.conf | ||
travis.yml | ||
update-documentation.sh | ||
update-target-fix-for-salt-ssh-to-process-targets-li.patch | ||
use-adler32-algorithm-to-compute-string-checksums.patch | ||
v3004.tar.gz | ||
x509-fixes-111.patch | ||
zypperpkg-ignore-retcode-104-for-search-bsc-1176697-.patch |
Salt-master as non-root user ============================ With this version of salt the salt-master will run as salt user. Why an extra user ================= While the current setup runs the master as root user, this is considered a security issue and not in line with the other configuration management tools (eg. puppet) which runs as a dedicated user. How can I undo the change ========================= If you would like to make the change before you can do the following steps manually: 1. change the user parameter in the master configuration user: root 2. update the file permissions: as root: chown -R root /etc/salt /var/cache/salt /var/log/salt /var/run/salt 3. restart the salt-master daemon: as root: rcsalt-master restart or systemctl restart salt-master NOTE ==== Running the salt-master daemon as a root user is considers by some a security risk, but running as root, enables the pam external auth system, as this system needs root access to check authentication. For more information: http://docs.saltstack.com/en/latest/ref/configuration/nonroot.html