(release-3006.28)=

Salt 3006.28 release notes{{ unreleased }}#

{{ warning }}

Hardened onedir layout opt-in (SALT_ONEDIR_HARDEN=1)#

3006.x adds an opt-in packaging mode that isolates each salt daemon's writable state under per-daemon directories:

  • /var/lib/salt/minion/{home,extras-<py>} for salt-minion

  • /var/lib/salt/master/{home,extras-<py>} for salt-master

  • /var/lib/salt/syndic/{home,extras-<py>} for salt-syndic

  • /var/lib/salt/api/{home,extras-<py>} for salt-api

  • /var/lib/salt/cloud/{home,extras-<py>} for salt-cloud

When the opt-in is selected, /opt/saltstack/salt stays owned by root:root at 0755 -- the packaging postinst / posttrans scriptlets no longer chown the tree to the salt user. On upgrade with the opt-in selected, existing /opt/saltstack/salt/extras-<py> contents migrate into the per-daemon /var/lib/salt/<daemon>/extras-<py> directory automatically.

salt-pip install and the runtime _salt_onedir_extras import hook honor the SALT_EXTRAS_DIR environment variable so packages installed via salt-pip continue to be importable by the daemon at runtime.

Opting in on 3006.x#

Set SALT_ONEDIR_HARDEN=1 in /etc/default/salt-setup (DEB) or /etc/sysconfig/salt-minion-setup (RPM) before installing or upgrading, then install/upgrade the salt packages. Existing installs migrate on the next package upgrade.

3006.x default is unchanged#

On 3006.x the default remains the legacy chown -R salt /opt/saltstack/salt behavior so existing deployments continue to work without intervention. The default flips to SALT_ONEDIR_HARDEN=1 on 3009.0. See {issue}70198.

Changelog#

{{ changelog }}