Building SaltStack - linux-on-ibm-z/docs GitHub Wiki
Below versions of SaltStack(Salt) are available in respective distributions at the time of creation of these build instructions:
- RHEL (9.6, 9.8) have
3005.4 - SLES 16 has
3006.0 - Ubuntu 22.04 has
3004.1
The instructions provided below specify the steps to build SaltStack(Salt) version 3008.2 on Linux on IBM Z for the following distributions:
- RHEL (8.10, 9.6, 9.8, 10.0, 10.2)
- SLES (15 SP7, 16)
- Ubuntu (22.04, 24.04)
General notes:
- When following the steps below please use a standard permission user unless otherwise specified.
- A directory
/<source_root>/will be referred to in these instructions, this is a temporary writable directory anywhere you'd like to place it.
If you want to build Salt using manual steps, go to STEP 2.
Use the following commands to build Salt using the build script. Please make sure you have wget installed.
wget -q https://raw.githubusercontent.com/linux-on-ibm-z/scripts/master/SaltStack/3008.2/build_salt.sh
# Build Salt
bash build_salt.sh [Provide -t for executing build with tests]
If the build completes successfully, go to STEP 5 to configure salt. In case of error, check logs for more details or go to STEP 2 to follow manual build steps.
export SOURCE_ROOT=/<source_root>/
export PATCH_URL="https://raw.githubusercontent.com/linux-on-ibm-z/scripts/master/SaltStack/3008.2/patch/"
-
RHEL (8.10)
sudo yum install -y procps-ng zeromq-devel cyrus-sasl-devel gcc gcc-c++ git libffi-devel libtool libxml2-devel libxslt-devel make man swig tar wget cmake bzip2-devel gdbm-devel libdb-devel libnsl2-devel libuuid-devel ncurses-devel openssl openssl-devel readline-devel sqlite-devel tk-devel xz xz-devel zlib-devel glibc-langpack-en diffutils cargo -
RHEL (9.6, 9.8)
sudo yum install -y procps-ng zeromq-devel cyrus-sasl-devel gcc gcc-c++ git rust cargo libffi-devel libtool libxml2-devel libxslt-devel make man openssl-devel swig tar wget cmake python3-devel python3-pip bzip2-devel sqlite-devel file iproute -
RHEL (10.0, 10.2)
sudo yum install -y procps-ng zeromq-devel cyrus-sasl-devel gcc gcc-c++ git rust cargo libffi-devel libtool libxml2-devel libxslt-devel make man openssl-devel tar wget cmake python3-devel python3-pip bzip2-devel sqlite-devel file iproute autoconf automake -
SLES (15 SP7, 16)
sudo zypper install -y curl cyrus-sasl-devel gawk gcc gcc-c++ git openssh-clients systemd python3-devel python3-pip libopenssl-devel libxml2-devel libxslt-devel make man tar wget cmake libnghttp2-devel gdbm-devel libbz2-devel libdb-4_8-devel libffi-devel libuuid-devel ncurses-devel readline-devel sqlite3-devel tk-devel xz-devel zlib-devel gzip bzip2 cargo
-
Ubuntu (22.04, 24.04)
sudo apt-get update sudo apt-get install -y wget g++ gcc git libffi-dev libsasl2-dev libssl-dev libxml2-dev libxslt1-dev make man tar libz-dev pkg-config apt-utils curl cmake libbz2-dev libdb-dev libgdbm-dev liblzma-dev libncurses-dev libreadline-dev libsqlite3-dev tk-dev uuid-dev xz-utils zlib1g-dev file iproute2 autoconf automake libtool
-
Install
Python 3.10.18cd $SOURCE_ROOT wget https://www.python.org/ftp/python/3.10.18/Python-3.10.18.tgz tar -xzf Python-3.10.18.tgz cd Python-3.10.18 ./configure --prefix=/usr/local --exec-prefix=/usr/local --enable-loadable-sqlite-extensions make sudo make install export PATH=/usr/local/bin/python3.10:$PATH sudo mkdir -p /usr/bin sudo ln -sf "$(command -v python3)" /usr/bin/python3 python3 -V -
Install M2Crypto (RHEL only)
- RHEL (8.10)
pip3 install "M2Crypto<0.40" -
RHEL (9.6, 9.8)
pip3 install M2CryptoNote: M2Crypto is skipped on RHEL 10+ (swig unavailable); Salt uses cryptography instead.
-
Install libzmq and pyzmq (SLES and Ubuntu only)
wget https://github.com/zeromq/libzmq/releases/download/v4.3.5/zeromq-4.3.5.tar.gz tar -xzf zeromq-4.3.5.tar.gz cd zeromq-4.3.5 ./configure make sudo make install sudo ldconfig pip3 install pyzmq -
Install Libgit2
cd $SOURCE_ROOT wget https://github.com/libgit2/libgit2/archive/refs/tags/v1.9.0.tar.gz tar xzf v1.9.0.tar.gz cd libgit2-1.9.0/ cmake . make sudo make install
-
Install OPENSSL3 (RHEL 8.10 only)
sudo yum install -y openssl3 openssl3-devel export OPENSSL_INCLUDE_DIR=/usr/include/openssl3 export OPENSSL_LIB_DIR=/usr/lib64/openssl3 export OPENSSL_NO_VENDOR=1 export LD_LIBRARY_PATH=/usr/lib64/openssl3:/usr/lib64:${LD_LIBRARY_PATH:-}
-
Install Python packages-
python3 -m pip install setuptools wheel && python3 -m pip wheel cassandra-driver==3.28.0 websocket-client==0.40.0 --no-build-isolation pip3 install pyzmq PyYAML cryptography==49.0.0 msgpack jinja2 psutil tornado python-dateutil genshi looseversion packaging distro
cd $SOURCE_ROOT
git clone --depth 1 -b v3008.2 https://github.com/saltstack/salt.git
cd salt
curl -sSL $PATCH_URL/salt.patch | git apply -
sed -i '/^lxml==/c\lxml==5.2.1' requirements/static/ci/py3.10/linux.lock
find requirements/static -name '*.lock' -exec sed -i 's/^protobuf==.*/protobuf==5.29.5/' {} +
echo 'protobuf>=5.29,<6' >> requirements/base.txt
pip3 install -e .See Salt upstream testing guide for details.
cd $SOURCE_ROOT/salt
sudo mkdir -p /var/log/salt /etc/salt/pki/minion /var/cache/salt/minion /var/run/salt /srv/salt
sudo chown -R $(whoami) /var/log/salt /etc/salt /var/cache/salt /var/run/salt /srv/salt
export SALT_FD_LEAK_TOLERANCE=20
pip3 install nox
python3 -m nox -e "test-3(coverage=False)" --install-only
for NOX_VENV in $(find .nox -maxdepth 1 -name 'test-*' -type d); do
if [ -f "$NOX_VENV/bin/activate" ]; then
source "$NOX_VENV/bin/activate"
pip install -e .
deactivate
fi
done
python3 -m nox -e "test-3(coverage=False)" --reuse-existing-virtualenvs -- --core-tests -o "asyncio_mode=auto"Note: A small number of flaky test failures may be observed (test_get_log_level_cli, test_jid_in_ret_event, test_chaos_partition_and_heal). These are upstream test-ordering or timing issues and pass on individual rerun.
Note (RHEL 10): RHEL 10's default crypto-policy disables SHA1 signatures. Salt's upstream code defaults to SHA1 for minion-master authentication, so some SHA1-specific tests will be skipped on RHEL 10. Users can set export OPENSSL_ENABLE_SHA1_SIGNATURES=1 to re-enable SHA1 if needed.
- Edit
$SOURCE_ROOT/salt/masterand$SOURCE_ROOT/salt/minion:
currentuser="$(whoami)"
sed -i "s/#user: root/user: $currentuser/" conf/master
sed -i 's,#root_dir: /,'"root_dir: $SOURCE_ROOT"',' conf/master
sed -i 's/#publish_port: 4505/publish_port: 4505/' conf/master
sed -i 's/#ret_port: 4506/ret_port: 4506/' conf/master
sed -i 's/#master: salt/master: localhost/' conf/minion
sed -i "s/#user: root/user: $currentuser/" conf/minion
sed -i 's,#root_dir: /,'"root_dir: $SOURCE_ROOT"',' conf/minion
sed -i 's/#master_port: 4506/master_port: 4506/' conf/minion
sed -i 's/#id:/id: saltdev/' conf/minionNote: If the ret_port value in the master config file is changed, set the same value to master_port value in the minion config file
- Now you can start your Salt master and minion, specifying the config dir.:
salt-master --config-dir=$SOURCE_ROOT/salt/conf --log-level=debug --daemon salt-minion --config-dir=$SOURCE_ROOT/salt/conf --log-level=debug --daemon
Note: If above command throws error salt-master: command not found then set PATH as export PATH=$SOURCE_ROOT/.local/bin:$PATH
install -y salt-master salt-minion salt-ssh salt-syndic salt-cloud salt-api
- Now you should be able to accept the minion key:
salt-key -c $SOURCE_ROOT/salt/conf -Ay - Check that your master/minion are communicating:
salt -c $SOURCE_ROOT/salt/conf \* test.version