Salt management questions

52 views
Skip to first unread message

Johannes Graumann

unread,
Feb 7, 2018, 9:27:39 AM2/7/18
to qubes-users
Gentlepeople,

For a while I have been managing a qubes setup using a dedicated
management VM and ansible via https://github.com/Rudd-O/ansible-qubes.
As auditing that code is beyond me and as salt is integral to qubes, I
was wondering whether that layout is currently possible using the salt
management stack, in other words: can the management stack (currently)
be used with a vm as the master to the entire system including dom0?

Sincerely, Joh

Johannes Graumann

unread,
Feb 12, 2018, 11:04:50 AM2/12/18
to qubes-users
I understand this may be IT-people-level stuff ..., but can anyone hint
at whether this is already possible and or where to look?

Joh

Johannes Graumann

unread,
Feb 14, 2018, 3:56:47 PM2/14/18
to qubes-users
Here https://www.qubes-os.org/news/2015/12/14/mgmt-stack/, Marek
Marczykowski-Górecki sais (referring to the core rewrite back then
ongoing for 4.)):
+ Then, based on this functionality, we will be able to create a
+ Management VM, which will allow secure, centralized management of
+ Qubes OS installations in an organization or company. But to do it
+ securely, we need to first finish some major rework of Qubes core
+ management code (“core3”), which is planned for Qubes 4.0. Then it
+ will be possible to implement Management VM in a way so that it will
+ have no access to user data, only ability to manage configuration of
+ (selected) VMs.
This is exactly what I want - plus limited tor/net connectivity to
track/backup my salt infrastructure in a gpg-encrypted git repo ...
Are we there yet?

Joh



Connor Page

unread,
Feb 15, 2018, 7:38:45 AM2/15/18
to qubes-users
Please consult
https://www.qubes-os.org/news/2017/06/27/qubes-admin-api/
https://www.qubes-os.org/news/2017/10/03/core3/
for more information about admin possibilities and how they’re supposed to work. There are simple demo examples as well.
Reply all
Reply to author
Forward
0 new messages