Salt Access Control
This section describes access control mechanisms for Salt in SUSE Multi-Linux Manager. It covers the distinction between SUSE Multi-Linux Manager Role-Based Access Control (RBAC) and native Salt access controls.
1. Architectural boundaries
SUSE Multi-Linux Manager separates access control into two distinct layers:
- SUSE Multi-Linux Manager RBAC (gateway layer)
-
Users interact with Salt features through the SUSE Multi-Linux Manager Web UI or API. SUSE Multi-Linux Manager verifies user identity and evaluates RBAC permissions before performing any Salt action. For example, running a command through requires the
salt.remote_commandsnamespace permission. For more information, see Role-Based Access Control (RBAC). - Native Salt access control (engine layer)
-
Salt provides built-in access control mechanisms, including external authentication (
external_authoreauth) and Publisher ACLs (publisher_acl). These mechanisms govern direct interactions with the Salt master daemon or the Salt API service.
2. External authentication (eauth)
The Salt API service (salt-api) runs on the SUSE Multi-Linux Manager Server.
By default, the service listens for HTTPS connections on port 9080, bound strictly to the local loopback interface (127.0.0.1).
Direct network access from external clients is blocked.
The Salt API uses the external_auth file authentication module:
-
Authentication credentials are stored in
/etc/salt/master.d/susemanager-users.txt. -
A dedicated internal administrative account is generated during server setup.
-
Only local system services (Tomcat and Taskomatic) use these credentials to communicate with the Salt API.
Individual SUSE Multi-Linux Manager users do not possess personal credentials for salt-api.
When a user initiates an action in the Web UI or API, SUSE Multi-Linux Manager authenticates the user, enforces RBAC checks, and executes the necessary Salt commands through the internal loopback connection.
3. Publisher ACLs
Upstream Salt provides Publisher ACLs (publisher_acl) to permit non-root system users to execute Salt commands from the SUSE Multi-Linux Manager Server command line.
publisher_acl maps individual system user names to the Salt execution modules they are permitted to run.
Users listed in publisher_acl can then publish those commands to Salt clients without root privileges.
As a filesystem prerequisite for this configuration, SUSE Multi-Linux Manager maintains group-read permissions (0640, group salt) on master configuration files such as /etc/salt/master.d/susemanager_engine.conf.
This configuration prevents permission denied errors when users in the salt group execute the salt command.
|
Salt commands run directly on the command line bypass SUSE Multi-Linux Manager RBAC checks. They are not tracked as SUSE Multi-Linux Manager actions and do not appear in the action history or the RBAC audit trail. Resulting changes on the client may not be reflected in the SUSE Multi-Linux Manager database until the next system refresh. For standard operations, execute Salt tasks through the Web UI or the SUSE Multi-Linux Manager API. |
4. Recommended access model
For all multi-user management and delegation, use SUSE Multi-Linux Manager RBAC instead of native Salt ACLs:
-
Create custom roles (access groups) in .
-
Grant granular permissions such as
salt.remote_commandsorsalt.keys. -
Assign users to access groups to enforce least privilege and preserve complete auditability.
For detailed instructions on configuring custom roles, see Role-Based Access Control (RBAC).