Skip to content

3.3.0-20260908 - #42

Merged
TOoSmOotH merged 17 commits into
3/mainfrom
3/dev
Sep 8, 2026
Merged

TOoSmOotH merged 17 commits into
3/mainfrom
3/dev

Conversation

@TOoSmOotH

Copy link
Copy Markdown
Contributor

No description provided.

dougburks and others added 17 commits August 20, 2026 13:53
securityonion now watches the directories under /opt/so/saltstack/local/salt/
that these pages tell users to edit, so hand-placed files are applied within
a few minutes instead of waiting for the next scheduled highstate.

Drop the Known Issues entry and turn the "not detected, so this step is
required" caveats on the zeek, elasticsearch, and rbac pages back into an
optional "if you don't want to wait" step.

Document the watched directories under Auto State Apply in salt.md, and say
plainly that anything else under local/salt/ still waits for the highstate.

Also correct two stale claims:
  - zeek.md said intel and zkg packages reach separate sensor nodes only at
    their next highstate. Auto State Apply targets every node running Zeek.
  - logstash.md said a defined_pipelines change waits for the next highstate.
    That is a SOC config save, which Auto State Apply has always detected.
Adds a tested walkthrough for serving a local OpenAI-compatible endpoint
for Onion AI on an AMD Strix Halo machine, using the packaged
GPU-accelerated llama.cpp rather than a hand-built stack.

The Hosting Local Models section of onion-ai.md previously offered only
"use LM Studio" and "you need at least 96GB of VRAM" with no procedure.
That VRAM figure is accurate for the large models listed above it but
misleading in general, so it is now scoped to those models and points at
the new page.

Every command and figure in the page was executed on the reference
hardware. Notable findings baked into the guide:

- The llama.cpp package ships its own llama-server systemd unit and
  /etc/default/llama-server config, so no custom unit is needed.
- The packaged _llama-server account cannot reach the GPU without being
  added to the render and video groups. Interactive shells work anyway
  because logind grants a per-user ACL on /dev/kfd and /dev/dri, so the
  failure is easy to miss: the service starts, looks healthy, and
  silently falls back to unusably slow CPU inference.
- Gemma 4 is a reasoning model and returns reasoning_content, leaving
  content empty until it finishes thinking. Too low a token limit yields
  an empty response, which reads as a broken endpoint.
- Q8_0 with the full 262144 token window uses only ~32 GB, and a fact at
  the start of a 193,139 token prompt was retrieved correctly.

vLLM was evaluated and rejected: gfx1151 is not in its supported GPU
list, there is no ROCm wheel, and every working reference builds from
source with patches inside a container. That is not a procedure worth
publishing.

Gemma 4 26B A4B is deliberately not added to the tested-models list in
onion-ai.md. It serves correctly and emits well-formed tool calls, but
it has not been exercised against an actual grid.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011MvtwjmU5wWs4rkPwKifNB
securityonion#16188 standardized on the Oracle UEK kernel and made
removal of the stock EL9 (RHCK) kernel automatic, so the page's manual
"dnf remove" recipe is no longer the way this happens.

Rewrites the page around the current behavior: so-kernel-upgrade to move
a node still on RHCK or UEK7 onto UEK8, why the RHCK removal is deferred
until after the reboot (dnf protects the running kernel), that the
highstate performs it, and so-kernel-upgrade --cleanup to trigger it by
hand. Notes that UEK7 5.x packages are left to age out on their own.
The page opened with the benefits of dropping the stock EL9 kernel, which
read as a pitch for doing something the admin no longer has to do. Says
up front that the move to UEK8 and the RHCK removal are automatic and
need no action, and moves so-kernel-upgrade into a "Doing It Manually"
section for the case where a node did not get there on its own.
…standardization

update Kernels page for UEK standardization
…pply-local-salt-files

Fix/auto state apply local salt files
@TOoSmOotH
TOoSmOotH merged commit 67b6182 into 3/main Sep 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants