Salt: Enable ext_pillar for minions in master/minion mode

Created on 11 Nov 2015  路  7Comments  路  Source: saltstack/salt

When using secret management systems like Confidant, it's better for minions to fetch their secrets directly, rather than having the master fetch the secrets, then distribute them to the minions. It would be nice to be able to use ext_pillar on minions directly, even if in master/minion mode (it already works in masterless). In this mode it should merge the pillars from the master with the ext_pillars from the minion.

Core Feature P3 Pillar stale

Most helpful comment

we should be able to do this by adding ext_pillar lookup in the RemotePillar class in salt/pillar/__init__.py

All 7 comments

Which would take precedence?

Ideally configurable. Default should probably be the minion overrides the master, since minion is more specific.

+100 this will indeed solve all my problems with ext_git + gpg (which has tons of issues)

@basepi would you please change the tag to Boron otherwise we'll have to way till same period next year - is going to be late for Salt as a project imo since with this feature you can promote the integration with other solutions (like one form Ryan) or the security of master/ minions

Hate to make "me too" comments but I would love to see this sooner than later. Fundamental part of secret sharing and potential differentiator for Salt.

we should be able to do this by adding ext_pillar lookup in the RemotePillar class in salt/pillar/__init__.py

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue.

Was this page helpful?
0 / 5 - 0 ratings