Reusing Salt State Configurations with Includes
When managing infrastructure with Salt, it's common to reuse certain configuration blocks across multiple systems. Salt allows modularization by defining shared states in separate files and including them in other SLS files as needed.
Example: Modularizing Apache Installation
Instead of repeating the installation steps for Apache, PHP, and related packages in every state file, extract them into a dedicated SLS file:
[root@master-1 web]# vim httpd.sls
lamp-install:
pkg.installed:
- pkgs:
- httpd
- php
- php-pdo
- php-mysql
Then, reference this file from the main LAMP configuration:
vim lamp.sls
include:
- web.httpd
# Apache configuration
apache-config:
file.managed:
- name: /etc/httpd/conf/httpd.conf
- source: salt://web/files/httpd.conf
- user: root
- group: root
- mode: 644
- template: jinja
- defaults:
PORT: 80
IPADDR: {{ grains['fqdn_ip4'][0] }}
- require:
- pkg: lamp-install
# Authentication setup
apache-auth:
pkg.installed:
- name: httpd-tools
- require_in:
- cmd: apache-auth
cmd.run:
- name: htpasswd -bc /etc/httpd/conf/htpasswd_file admin admin
- unless: test -f /etc/httpd/conf/htpasswd_file
# Configuration directory
apache-conf:
file.recurse:
- name: /etc/httpd/conf.d
- source: salt://web/files/apache-conf.d
# PHP configuration
php-config:
file.managed:
- name: /etc/php.ini
- source: salt://web/files/php.ini
- user: root
- group: root
- mode: 644
# Service management
lamp-service:
service.running:
- name: httpd
- enable: True
- reload: True
- watch:
- file: apache-conf
- file: apache-config
Example: Seaprating Tomcat Installation and JDK Setup
Similarly, for Java-based services like Tomcat, modularize the JDK installation:
vim jdk.sls
jdk-install:
file.managed:
- name: /usr/local/src/jdk-8u181-linux-x64.tar.gz
- source: salt://web/files/jdk-8u181-linux-x64.tar.gz
cmd.run:
- name: cd /usr/local/src && tar zxf jdk-8u181-linux-x64.tar.gz -C /usr/local/
- unless: test -f /usr/local/src/jdk-8u181-linux-x64.tar.gz && test -d /usr/local/jdk1.8.0_181
/etc/profile:
file.append:
- text:
- "export JAVA_HOME=/usr/local/jdk1.8.0_181"
- "export JRE_HOME=/usr/local/jdk1.8.0_181/jre"
- "export PATH=$JAVA_HOME/bin:$JRE_HOME/bin:$PATH"
Then include it in the Tomcat state:
vim tomcat.sls
include:
- web.jdk
tomcat-install:
file.managed:
- name: /usr/local/src/apache-tomcat-8.0.46.tar.gz
- source: salt://web/files/apache-tomcat-8.0.46.tar.gz
- user: root
- group: root
- mode: 755
cmd.run:
- name: cd /usr/local/src && tar zxf apache-tomcat-8.0.46.tar.gz -C /usr/local/ && ln -s /usr/local/apache-tomcat-8.0.46 /usr/local/tomcat
- unless: test -L /usr/local/tomcat && test -d /usr/local/apache-tomcat-8.0.46
Test the configuration before applying it:
salt master-2 state.sls web.tomcat test=True
salt master-2 state.sls web.tomcat
Changing Minion ID in SaltStack
To update a minion's ID in SaltStack, follow these steps:
- Stop the minion service.
- On the master, remove the old key: ```
salt-key -d minionid
- On the minion, remove the old ID and keys: ```
rm -fr /etc/salt/minion_id
rm -fr /etc/salt/pki
- Edit the minion configuration file (
/etc/salt/minion) to udpate the ID, or change the hostname by editing/etc/hostnameand/etc/hosts. - Restart the minion service.
- Restart the Salt master to clear cached keys.
- Accept the new key: ```
salt-key -A