Modularizing Salt States with Includes and Minion ID Management

Reusing Salt State Configurations with Includes

When managing infrastructure with Salt, it's common to reuse certain configuration blocks across multiple systems. Salt allows modularization by defining shared states in separate files and including them in other SLS files as needed.

Example: Modularizing Apache Installation

Instead of repeating the installation steps for Apache, PHP, and related packages in every state file, extract them into a dedicated SLS file:

[root@master-1 web]# vim httpd.sls

lamp-install:
  pkg.installed:
    - pkgs:
      - httpd
      - php
      - php-pdo
      - php-mysql

Then, reference this file from the main LAMP configuration:

vim lamp.sls

include:
  - web.httpd

# Apache configuration
apache-config:
  file.managed:
    - name: /etc/httpd/conf/httpd.conf
    - source: salt://web/files/httpd.conf
    - user: root
    - group: root
    - mode: 644
    - template: jinja
    - defaults:
      PORT: 80
      IPADDR: {{ grains['fqdn_ip4'][0] }}
    - require:
      - pkg: lamp-install

# Authentication setup
apache-auth:
  pkg.installed:
    - name: httpd-tools
    - require_in:
      - cmd: apache-auth
  cmd.run:
    - name: htpasswd -bc /etc/httpd/conf/htpasswd_file admin admin
    - unless: test -f /etc/httpd/conf/htpasswd_file

# Configuration directory
apache-conf:
  file.recurse:
    - name: /etc/httpd/conf.d
    - source: salt://web/files/apache-conf.d

# PHP configuration
php-config:
  file.managed:
    - name: /etc/php.ini
    - source: salt://web/files/php.ini
    - user: root
    - group: root
    - mode: 644

# Service management
lamp-service:
  service.running:
    - name: httpd
    - enable: True
    - reload: True
    - watch:
      - file: apache-conf
      - file: apache-config

Example: Seaprating Tomcat Installation and JDK Setup

Similarly, for Java-based services like Tomcat, modularize the JDK installation:

vim jdk.sls

jdk-install:
  file.managed:
    - name: /usr/local/src/jdk-8u181-linux-x64.tar.gz
    - source: salt://web/files/jdk-8u181-linux-x64.tar.gz
  cmd.run:
    - name: cd /usr/local/src && tar zxf jdk-8u181-linux-x64.tar.gz -C /usr/local/
    - unless: test -f /usr/local/src/jdk-8u181-linux-x64.tar.gz && test -d /usr/local/jdk1.8.0_181
/etc/profile:
  file.append:
    - text:
      - "export JAVA_HOME=/usr/local/jdk1.8.0_181"
      - "export JRE_HOME=/usr/local/jdk1.8.0_181/jre"
      - "export PATH=$JAVA_HOME/bin:$JRE_HOME/bin:$PATH"

Then include it in the Tomcat state:

vim tomcat.sls

include:
  - web.jdk

tomcat-install:
  file.managed:
    - name: /usr/local/src/apache-tomcat-8.0.46.tar.gz
    - source: salt://web/files/apache-tomcat-8.0.46.tar.gz
    - user: root
    - group: root
    - mode: 755
  cmd.run:
    - name: cd /usr/local/src && tar zxf apache-tomcat-8.0.46.tar.gz -C /usr/local/ && ln -s /usr/local/apache-tomcat-8.0.46 /usr/local/tomcat
    - unless: test -L /usr/local/tomcat && test -d /usr/local/apache-tomcat-8.0.46

Test the configuration before applying it:

salt master-2 state.sls web.tomcat test=True
salt master-2 state.sls web.tomcat

Changing Minion ID in SaltStack

To update a minion's ID in SaltStack, follow these steps:

  1. Stop the minion service.
  2. On the master, remove the old key: ``` salt-key -d minionid
  3. On the minion, remove the old ID and keys: ``` rm -fr /etc/salt/minion_id rm -fr /etc/salt/pki
  4. Edit the minion configuration file (/etc/salt/minion) to udpate the ID, or change the hostname by editing /etc/hostname and /etc/hosts.
  5. Restart the minion service.
  6. Restart the Salt master to clear cached keys.
  7. Accept the new key: ``` salt-key -A

Tags: SaltStack configuration-management modularization server-administration infrastructure-automation

Posted on Wed, 07 Oct 2026 16:32:39 +0000 by pesoto74