salt minion module writes minion keys to the wrong directory
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
cloud-init |
Fix Released
|
Medium
|
Unassigned | ||
cloud-init (Ubuntu) |
Fix Released
|
Medium
|
Unassigned | ||
Xenial |
Fix Released
|
Medium
|
Unassigned |
Bug Description
==== Begin SRU Template ====
[Impact]
Salt minion config module of cloud-init would not work by default
if 'public_key' and 'private_key' were provided.
[Test Case]
## Recreate failure
$ cat >user-data <<EOF
#cloud-config
salt_minion:
public_key: "foo public"
private_key: "foo private"
EOF
$ lxc launch ubuntu-daily:xenial x1 "--config=
$ lxc exec x1 -- grep salt/pki/ /var/log/
Sep 13 21:04:55 ubuntu [CLOUDINIT] util.py[DEBUG]: Writing to /etc/salt/
Sep 13 21:04:55 ubuntu [CLOUDINIT] util.py[DEBUG]: Writing to /etc/salt/
## Note, that ubuntu's packaging actuall moves these files to their proper
## location, so checking the log is all we can do to show failure.
## Now update container, clean and reboot to show first boot
$ lxc exec x1 -- sh -c '
p=/
echo deb http://
apt-get update -q && apt-get -qy install cloud-init'
$ lxc exec x1 -- sh -c 'apt-get -qy --purge remove salt-minion && rm -Rf /etc/salt'
$ lxc exec x1 -- sh -c '
cd /var/lib/cloud && for d in *; do [ "$d" = "seed" ] || rm -Rf "$d"; done
rm -Rf /var/log/
$ lxc exec x1 reboot
$ lxc exec x1 -- grep salt/pki/ /var/log/
Sep 13 21:10:52 x1 [CLOUDINIT] util.py[DEBUG]: Writing to /etc/salt/
Sep 13 21:10:52 x1 [CLOUDINIT] util.py[DEBUG]: Writing to /etc/salt/
[Regression Potential]
Low chance for regression, especially since the packaging does the right thing.
==== End SRU Template ====
Cloud-init's salt minion module writes minion.pem, and minion.pub to the wrong directory. Salt-minion expects them in /etc/salt/
Current:
pki_dir = salt_cfg.
Fixed:
pki_dir = salt_cfg.
Related branches
- Ryan Harper: Approve
-
Diff: 18 lines (+6/-1)1 file modifiedcloudinit/config/cc_salt_minion.py (+6/-1)
Changed in cloud-init: | |
status: | Confirmed → Fix Committed |
Changed in cloud-init (Ubuntu): | |
status: | New → Fix Released |
importance: | Undecided → Medium |
Changed in cloud-init (Ubuntu Xenial): | |
status: | New → In Progress |
importance: | Undecided → Medium |
description: | updated |
The answer to the mystery is that cloud-init's salt minion module was originally written for salt two years ago when /etc/salt/pki was the path. At some point the changes to /etc/salt/ pki/minion, and added an auto migration function. But the auto migration function is wrapped in an if statement that says only run it if the transport is zeromq. The default transport seems to not be zeromq anymore, so the migration no longer runs.
I am going to file a bug with salt, but cloud-init should still be fixed to use the new path. Then it won't depend on the migration.