also sprach Corey Quinn <
co...@sequestered.net> [2014-01-04 13:14 +1300]:
> To answer the question of why Salt was designed this way, it's
> generally easier to expose one server than "all of them" in most
> environments. You can also get fairly restrictive with ACLs.
It would, IMHO, be best if I could choose per-minion whether it will
contact the master, or whether it expects the master to establish
a link to the minion, and a way to set a default.
And then, everything should go via a single, long-lived connection,
instead of the control/data separation that we have come to loathe
from the days of FTP.
On my wishlist for Salt 1.0… that, and the ability to use
roster-type commandeering of the nodes, rather than pubsub, which
the clients can choose to ignore (e.g. because of network hiccoughs)
without the master knowing…
--
martin |
http://madduck.net/ |
http://two.sentenc.es/
half a bee, philosophically, must ipso facto half not be.
but half the bee has got to be, vis-a-vis its entity. you see?
but can a bee be said to be or not to be an entire bee,
when half the bee is not a bee, due to some ancient injury?
-- monty python
spamtraps:
madduc...@madduck.net