Some background information, I am new to provisioning and followed this tutorial:
It explains how to setup a salt-master and salt-minion remotely by using a salt-cloud setup. It also refers a few security measures, setting up a different port for ssh, switching of root access and creating a different user with root permissions for usage, last but not least, setting up a firewall that opens the custom ssh port and ports 4505, 4506 which are used by salt.
Question
The article doesn't say anything about this, but shouldn't the same security measures be taken into consideration for the minions?
The bootstrap.sh script (that is used to hoist the minion(s)) doesn't seem to implement those settings (eg. running sudo salt 'minion01' cmd.run 'cat /etc/ssh/sshd_config' shows me port 22 is used and root access is permitted for the minion. Also sudo salt '*' cmd.run 'ufw verbose status' shows there's no firewall is installed