Both Debian and CentOS packages provide a service with a timer to automate the renewal, so we don't need this but to prune our code, and move the nginx reload information to the renewal config.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
All Stories
Aug 4 2024
Use admin role
To be able to use auth/token/create/admin, it needs a role admin, let's add it to the DRP bootstrap script:
hunt-insecable-spaces
Just a small note this product becomes more and more open core, and we're less in favour of that one "specifically".
Aug 3 2024
https://www.incits.org/dotAsset/29643f45-86d8-4137-987e-9685b944d1e0.pdf can now be used instead.
I've saved test run log earlier this afternoon, here it is:
Works fine.
Per previous comment, I'd advice to downgrade to 3006 LTS for paas-docker servers too.
We're downgrading to Salt 3006 on Linux servers to still be able to distribute credentials from 3006 server.
I've also discovered we can't deploy secrets to Salt 3007+ anymore from a Salt 3006 server:
Unit wanted to overwrite Eglide-specific Vault Salt configuration, I've opened T1998 for follow-up.
$ salt-call --local state.apply roles/core/salt test=True […] ---------- ID: /etc/apt/keyrings/salt-archive-keyring-2023.gpg Function: file.managed Result: True Comment: The file /etc/apt/keyrings/salt-archive-keyring-2023.gpg is in the correct state Started: 16:25:09.653065 Duration: 7.356 ms Changes: ---------- ID: /etc/apt/sources.list.d/salt.list Function: file.managed Result: True Comment: The file /etc/apt/sources.list.d/salt.list is in the correct state Started: 16:25:09.660512 Duration: 1.221 ms Changes: […]
$ salt dwellers state.apply hotfixes/salt dwellers: ---------- ID: T1991_egrep_patch Function: file.patch Name: /opt/saltstack/salt/lib/python3.10/site-packages/salt Result: True Comment: Patch successfully applied Started: 16:15:53.189797 Duration: 45.172 ms Changes: ---------- pid: 4123780 retcode: 0 stderr: stdout: patching file modules/csf.py patching file modules/selinux.py
From router-001 network looks good:
Stopped currently not needed salt and node-exporter on router-001 to see if that helps.
Could be at hypervisor level. SSH failed until 13:22 where it worked immediately.
As of 13:18 UTC, SSH access works.
Also, at the same time, DevCentral is slow for arc diff or to publish this task. This delay behavior is similar as when DNS resolution timeouts occur.
$ salt-minion --versions Salt Version: Salt: 3007.1
We can actually provide P352 as hotfix.
Ok, with wget/wget2 transition still problematic (unrelated to patch package).
patch is available on Eglide as part of build-essential, so presumed OK for Debian