Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-18 Thread Andrew David Wong
On 10/17/20 10:29 PM, icequbes1 wrote: Oct 17, 2020, 21:12 by j...@vt.edu: On Fri, Oct 16, 2020 at 9:22 PM 'icequbes1' via qubes-devel wrote: While the docs are very nice, sometimes I think there is too much documentation in Qubes that it might scare new users away. I must strongly

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread 'icequbes1' via qubes-devel
Oct 17, 2020, 21:12 by j...@vt.edu: > On Fri, Oct 16, 2020 at 9:22 PM 'icequbes1' via qubes-devel > wrote: > >> >> While the docs are very nice, sometimes I think there is too much >> documentation in Qubes that it might scare new users away. >> > > I must strongly disagree. > ...> It's useful

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread Jean-Philippe Ouellet
On Fri, Oct 16, 2020 at 9:22 PM 'icequbes1' via qubes-devel wrote: > > Oct 16, 2020, 02:54 by a...@qubes-os.org: > > > On 10/13/20 11:51 AM, Rafael Reis wrote: > > > >> It'd be useful if those qubesctl update commands were in the docs, > >> especially with the concurrency option. > >> > > > >

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread Andrew David Wong
On 10/16/20 11:17 AM, Chris Laprise wrote: On 10/16/20 5:56 AM, Andrew David Wong wrote: On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread Andrew David Wong
On 10/16/20 9:22 PM, icequbes1 wrote: Oct 16, 2020, 02:54 by a...@qubes-os.org: On 10/13/20 11:51 AM, Rafael Reis wrote: It'd be useful if those qubesctl update commands were in the docs, especially with the concurrency option. I've just added them:

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread David Hobach
On 10/17/20 6:22 AM, 'icequbes1' via qubes-devel wrote: While the docs are very nice, sometimes I think there is too much documentation in Qubes that it might scare new users away. While some users may be unaware of the ability to update TemplateVMs with qubesctl, is a _typical_ user really

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread 'icequbes1' via qubes-devel
Oct 16, 2020, 02:54 by a...@qubes-os.org: > On 10/13/20 11:51 AM, Rafael Reis wrote: > >> It'd be useful if those qubesctl update commands were in the docs, >> especially with the concurrency option. >> > > I've just added them: > > https://www.qubes-os.org/doc/salt/#updatequbes-dom0 >

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Demi M. Obenour
On 10/16/20 2:17 PM, Chris Laprise wrote: > I'm recalling times when I received a cryptic error message that the update > failed (no detail). In these cases I would just go back to my update script > and then the update(s) would succeed. So this is not something I tried to > troubleshoot, and

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Chris Laprise
On 10/16/20 5:56 AM, Andrew David Wong wrote: On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: On 10/11/20 11:16 AM, Marek

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: On Sat, Oct 10, 2020 at

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
On 10/13/20 11:51 AM, Rafael Reis wrote: It'd be useful if those qubesctl update commands were in the docs, especially with the concurrency option. I've just added them: https://www.qubes-os.org/doc/salt/#updatequbes-dom0 https://www.qubes-os.org/doc/salt/#updatequbes-vm In case you (or any

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
On 10/11/20 5:58 PM, Marek Marczykowski-Górecki wrote: [...] And then for TemplateVM and StandaloneVM (all at once): sudo qubesctl --skip-dom0 --templates --standalones state.sls update.qubes-vm Useful options: --max-concurrency - limit how many templates are updated at the same

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-14 Thread Chris Laprise
On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote:

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-13 Thread Rafael Reis
It'd be useful if those qubesctl update commands were in the docs, especially with the concurrency option. Em domingo, 11 de outubro de 2020 às 13:16:43 UTC-3, marm...@invisiblethingslab.com escreveu: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Sat, Oct 10, 2020 at 09:50:00PM

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: > On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: > > On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: > > > I still upgrade dom0 and templates the

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Andrew David Wong
On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: I still upgrade dom0 and templates the old-fashioned way, because I'm used to it, I understand it, and I already have custom scripts for daily maintenance that include

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: > I still upgrade dom0 and templates the old-fashioned way, because I'm > used to it, I understand it, and I already have custom scripts for daily > maintenance that include these

[qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-10 Thread Andrew David Wong
I still upgrade dom0 and templates the old-fashioned way, because I'm used to it, I understand it, and I already have custom scripts for daily maintenance that include these commands. Specifically, I mean these kinds of commands: `sudo qubes-dom0-update -y` in a dom0 terminal `dnf -y --refresh