(release-3006.28)=
{{ warning }}
SALT_ONEDIR_HARDEN=1)¶3006.x adds an opt-in packaging mode that isolates each salt daemon's writable state under per-daemon directories:
/var/lib/salt/minion/{home,extras-<py>} for salt-minion
/var/lib/salt/master/{home,extras-<py>} for salt-master
/var/lib/salt/syndic/{home,extras-<py>} for salt-syndic
/var/lib/salt/api/{home,extras-<py>} for salt-api
/var/lib/salt/cloud/{home,extras-<py>} for salt-cloud
When the opt-in is selected, /opt/saltstack/salt stays owned by
root:root at 0755 -- the packaging postinst / posttrans scriptlets
no longer chown the tree to the salt user. On upgrade with the opt-in
selected, existing /opt/saltstack/salt/extras-<py> contents migrate
into the per-daemon /var/lib/salt/<daemon>/extras-<py> directory
automatically.
salt-pip install and the runtime _salt_onedir_extras import hook
honor the SALT_EXTRAS_DIR environment variable so packages installed
via salt-pip continue to be importable by the daemon at runtime.
Set SALT_ONEDIR_HARDEN=1 in /etc/default/salt-setup (DEB) or
/etc/sysconfig/salt-minion-setup (RPM) before installing or
upgrading, then install/upgrade the salt packages. Existing installs
migrate on the next package upgrade.
On 3006.x the default remains the legacy chown -R salt /opt/saltstack/salt
behavior so existing deployments continue to work without intervention.
The default flips to SALT_ONEDIR_HARDEN=1 on 3009.0. See
{issue}70198.
{{ changelog }}