ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Salt-Minion can't talk to Salt-Master

    IT Discussion
    salt-minion salt-master salt minion salt stack salt saltstack
    7
    41
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NerdyDadN
      NerdyDad
      last edited by NerdyDad

      I have 2 physically separate boxes on the same LAN, 1 Fedora 29 server and 1 Fedora 29 Gnome desktop.

      Server updated and installed salt-master and changed its name to SaltMaster (creative, I know)

      Desktop updated and installed salt-minion (Name was already set from a previous Windows install and Fedora just carried it over)

      Services are running on both boxes, changed the config on the minion to the network name of the SaltMaster

      Minion can ping the master box with DNS and IP address but doesn't see the service and the master box isn't registering any unaccepted keys. I have tried adding 4505-4506 TCP to the firewall, but still no change. Restarted the salt-master service and firewall service, rebooted the SaltMaster server, and restarted the salt-minion service.

      Still no communications. Any ideas?

      1 Reply Last reply Reply Quote 0
      • black3dynamiteB
        black3dynamite
        last edited by black3dynamite

        Will you show the command for adding the firewall rules for 4505-5606?
        The reason I'm asking is because if you include --zone=FedoraServer but your active firewall zone is public then that could be the issue.

        NerdyDadN 1 Reply Last reply Reply Quote 0
        • NerdyDadN
          NerdyDad @black3dynamite
          last edited by

          @black3dynamite said in Salt-Minion can't talk to Salt-Master:

          Will you show the command for adding the firewall rules for 4505-5606?
          The reason I'm asking is because if you include --zone=FedoraServer but your active firewall zone is public then that could be the issue.

          I've tried a number of commands

          firewall-cmd --permanent --zone=trusted --add-port=4505-4506/tcp
          firewall-cmd --permanent --zone=default --add-port=4505-4506/tcp
          firewall-cmd --permanent --add-port=4505-4506/tcp

          In that order, but not all at the same time. I reloaded the firewall and retested between each line.

          DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @NerdyDad
            last edited by

            @NerdyDad if you run firewall-cmd --get-active-zones what is the output?

            NerdyDadN 2 Replies Last reply Reply Quote 0
            • NerdyDadN
              NerdyDad @DustinB3403
              last edited by

              @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

              @NerdyDad if you run firewall-cmd --get-active-zones what is the output?

              FedoraServer
              interfaces: enp3s0

              DustinB3403D 1 Reply Last reply Reply Quote 0
              • NerdyDadN
                NerdyDad @DustinB3403
                last edited by

                @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                @NerdyDad if you run firewall-cmd --get-active-zones what is the output?

                So I gather that FedoraServer is the zone that I need to add the ports to in the firewall?

                1 Reply Last reply Reply Quote 0
                • DustinB3403D
                  DustinB3403 @NerdyDad
                  last edited by

                  @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                  @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                  @NerdyDad if you run firewall-cmd --get-active-zones what is the output?

                  FedoraServer
                  interfaces: enp3s0

                  Did you create a custom zone called FedoraServer?

                  NerdyDadN 1 Reply Last reply Reply Quote 0
                  • NerdyDadN
                    NerdyDad @DustinB3403
                    last edited by

                    @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                    @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                    @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                    @NerdyDad if you run firewall-cmd --get-active-zones what is the output?

                    FedoraServer
                    interfaces: enp3s0

                    Did you create a custom zone called FedoraServer?

                    No, I have not created any zones yet. That came stock.

                    1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403
                      last edited by

                      If your output of firewall-cmd --get-active-zones is FedoraServer interfaces: enp3s0 then yes, add the rules to that zone.

                      1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        firewall-cmd --permanent --zone=FedoraServer --add-port=4505-4506/tcp

                        Should be what you're looking for.

                        NerdyDadN 1 Reply Last reply Reply Quote 1
                        • DustinB3403D
                          DustinB3403
                          last edited by

                          Then you need to reload the firewall and test.

                          1 Reply Last reply Reply Quote 0
                          • NerdyDadN
                            NerdyDad @DustinB3403
                            last edited by

                            @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                            firewall-cmd --permanent --zone=FedoraServer --add-port=4505-4506/tcp

                            Should be what you're looking for.

                            Did that and says it is already enabled.

                            1 Reply Last reply Reply Quote 0
                            • NerdyDadN
                              NerdyDad
                              last edited by NerdyDad

                              Is the salt master service looking at the correct zone? Is that the right way to think of it?

                              1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403
                                last edited by

                                And you've reloaded the firewall with firewall-cmd --reload?

                                NerdyDadN 1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403
                                  last edited by

                                  Well going into the salt master config file you'd have to look and see if it's set correctly.

                                  https://docs.saltstack.com/en/latest/ref/configuration/master.html

                                  1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403
                                    last edited by

                                    Just for laughs check the status of setenforce.

                                    1 Reply Last reply Reply Quote 0
                                    • NerdyDadN
                                      NerdyDad @DustinB3403
                                      last edited by

                                      @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                      And you've reloaded the firewall with firewall-cmd --reload?

                                      Still not working

                                      @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                      Just for laughs check the status of setenforce.

                                      Enforcing

                                      DustinB3403D 1 Reply Last reply Reply Quote 0
                                      • DustinB3403D
                                        DustinB3403 @NerdyDad
                                        last edited by

                                        @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                                        @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                        And you've reloaded the firewall with firewall-cmd --reload?

                                        Still not working

                                        @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                        Just for laughs check the status of setenforce.

                                        Enforcing

                                        Try setting setenforce to permissive or disabled for now and test.

                                        NerdyDadN 1 Reply Last reply Reply Quote 0
                                        • NerdyDadN
                                          NerdyDad @DustinB3403
                                          last edited by

                                          @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                          @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                                          @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                          And you've reloaded the firewall with firewall-cmd --reload?

                                          Still not working

                                          @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                          Just for laughs check the status of setenforce.

                                          Enforcing

                                          Try setting setenforce to permissive or disabled for now and test.

                                          Finally, got the minion to talk to the master. Thanks

                                          dafyreD DustinB3403D 2 Replies Last reply Reply Quote 0
                                          • dafyreD
                                            dafyre @NerdyDad
                                            last edited by

                                            @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                                            @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                            @NerdyDad said in Salt-Minion can't talk to Salt-Master:

                                            @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                            And you've reloaded the firewall with firewall-cmd --reload?

                                            Still not working

                                            @DustinB3403 said in Salt-Minion can't talk to Salt-Master:

                                            Just for laughs check the status of setenforce.

                                            Enforcing

                                            Try setting setenforce to permissive or disabled for now and test.

                                            Finally, got the minion to talk to the master. Thanks

                                            Was it SELinux?

                                            NerdyDadN 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post