Repository navigation
Conversation
securityonion now watches the directories under /opt/so/saltstack/local/salt/
that these pages tell users to edit, so hand-placed files are applied within
a few minutes instead of waiting for the next scheduled highstate.
Drop the Known Issues entry and turn the "not detected, so this step is
required" caveats on the zeek, elasticsearch, and rbac pages back into an
optional "if you don't want to wait" step.
Document the watched directories under Auto State Apply in salt.md, and say
plainly that anything else under local/salt/ still waits for the highstate.
Also correct two stale claims:
- zeek.md said intel and zkg packages reach separate sensor nodes only at
their next highstate. Auto State Apply targets every node running Zeek.
- logstash.md said a defined_pipelines change waits for the next highstate.
That is a SOC config save, which Auto State Apply has always detected.
Adds a tested walkthrough for serving a local OpenAI-compatible endpoint for Onion AI on an AMD Strix Halo machine, using the packaged GPU-accelerated llama.cpp rather than a hand-built stack. The Hosting Local Models section of onion-ai.md previously offered only "use LM Studio" and "you need at least 96GB of VRAM" with no procedure. That VRAM figure is accurate for the large models listed above it but misleading in general, so it is now scoped to those models and points at the new page. Every command and figure in the page was executed on the reference hardware. Notable findings baked into the guide: - The llama.cpp package ships its own llama-server systemd unit and /etc/default/llama-server config, so no custom unit is needed. - The packaged _llama-server account cannot reach the GPU without being added to the render and video groups. Interactive shells work anyway because logind grants a per-user ACL on /dev/kfd and /dev/dri, so the failure is easy to miss: the service starts, looks healthy, and silently falls back to unusably slow CPU inference. - Gemma 4 is a reasoning model and returns reasoning_content, leaving content empty until it finishes thinking. Too low a token limit yields an empty response, which reads as a broken endpoint. - Q8_0 with the full 262144 token window uses only ~32 GB, and a fact at the start of a 193,139 token prompt was retrieved correctly. vLLM was evaluated and rejected: gfx1151 is not in its supported GPU list, there is no ROCm wheel, and every working reference builds from source with patches inside a container. That is not a procedure worth publishing. Gemma 4 26B A4B is deliberately not added to the tested-models list in onion-ai.md. It serves correctly and emits well-formed tool calls, but it has not been exercised against an actual grid. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011MvtwjmU5wWs4rkPwKifNB
…osting add Local LLM Hosting guide
securityonion#16188 standardized on the Oracle UEK kernel and made removal of the stock EL9 (RHCK) kernel automatic, so the page's manual "dnf remove" recipe is no longer the way this happens. Rewrites the page around the current behavior: so-kernel-upgrade to move a node still on RHCK or UEK7 onto UEK8, why the RHCK removal is deferred until after the reboot (dnf protects the running kernel), that the highstate performs it, and so-kernel-upgrade --cleanup to trigger it by hand. Notes that UEK7 5.x packages are left to age out on their own.
The page opened with the benefits of dropping the stock EL9 kernel, which read as a pitch for doing something the admin no longer has to do. Says up front that the move to UEK8 and the RHCK removal are automatic and need no action, and moves so-kernel-upgrade into a "Doing It Manually" section for the case where a node did not get there on its own.
…standardization update Kernels page for UEK standardization
Cogburn/memory
…pply-local-salt-files Fix/auto state apply local salt files
dougburks
approved these changes
Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.