Install in air-gapped environments#

The Salt Project provides public repositories for packages on the public Broadcom Artifactory endpoint:

The preferred method for installing Salt is using distribution packages. This method ensures that:

  • All dependencies are met.

  • Salt is installed in a tested and distribution-aligned way.

Note

Salt is often distributed in split packages, but only the salt-master and salt-minion packages are required for Salt to function. If only desiring to run Salt in a masterless setup, then only salt-minion is required.

About air-gapped installations#

To install Salt in an air-gapped environment, you can create a local mirror of the Salt Project repositories using a sync tool such as rclone or wget.

Create a local mirror with rclone (faster)#

Note

Only sync once per day.

Important

Always pass the -c / --checksum flag to rclone sync. Without it, rclone compares files by size and modification time only. The Salt package repositories publish updates in which small companion files (*.md5, *.sha1, *.sha256, Release, Release.gpg, InRelease, and the RPM repodata/repomd.xml) can keep the same size while their content changes, so a size+mtime comparison silently skips them. The stale hash/metadata files then cause apt (and yum/dnf) to reject the mirror with “unexpected size” / hash-mismatch errors. See issue 69652 for the original report.

To set up local mirrors with rclone:

Syncs down the following repo: saltproject-rpm

In the rclone command line, adapt this example:

RCLONE_WEBDAV_URL=https://packages.broadcom.com/artifactory/ RCLONE_WEBDAV_VENDOR=other rclone sync --fast-list --checksum -v :webdav:saltproject-rpm/ ./saltproject-rpm/

Syncs down the following repo: saltproject-deb

In the rclone command line, adapt this example:

RCLONE_WEBDAV_URL=https://packages.broadcom.com/artifactory/ RCLONE_WEBDAV_VENDOR=other rclone sync --fast-list --checksum -v :webdav:saltproject-deb/ ./saltproject-deb/

Syncs down the following repo: saltproject-generic

In the rclone command line, adapt this example:

RCLONE_WEBDAV_URL=https://packages.broadcom.com/artifactory/ RCLONE_WEBDAV_VENDOR=other rclone sync --fast-list --checksum -v :webdav:saltproject-generic/ ./saltproject-generic/

Create a local mirror with wget (slower)#

Note

Only sync once per day.

To set up local mirrors with wget:

Syncs down the following repo: saltproject-rpm

In the wget command line, adapt this example:

wget --mirror -nH --cut-dirs=1 https://packages.broadcom.com/artifactory/saltproject-rpm/

Syncs down the following repo: saltproject-deb

In the wget command line, adapt this example:

wget --mirror -nH --cut-dirs=1 https://packages.broadcom.com/artifactory/saltproject-deb/

Syncs down the following repo: saltproject-generic

In the wget command line, adapt this example:

wget --mirror -nH --cut-dirs=1 https://packages.broadcom.com/artifactory/saltproject-generic/