Skip to content

Commit

Permalink
Add state to route all updates through Whonix
Browse files Browse the repository at this point in the history
As discussed in QubesOS/qubes-issues#2604, lets have a state for
switching just updates, not all the traffic.

Fixes QubesOS/qubes-issues#2604
  • Loading branch information
marmarek committed Oct 7, 2017
1 parent d17f665 commit a0cbb48
Show file tree
Hide file tree
Showing 4 changed files with 32 additions and 0 deletions.
4 changes: 4 additions & 0 deletions README.rst
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,10 @@ Whonix workstation AppVM.
-------------------
Whonix workstation AppVM for Whonix Disposable VMs.

``qvm.updates-via-whonix``
-------------------
Setup UpdatesProxy to route all templates updates through Tor (sys-whonix here).

``qvm.template-fedora-21``
--------------------------
Fedora-21 TemplateVM
Expand Down
19 changes: 19 additions & 0 deletions qvm/updates-via-whonix.sls
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# -*- coding: utf-8 -*-
# vim: set syntax=yaml ts=2 sw=2 sts=2 et :

##
# qvm.updates-via-whonix
# ===============
#
# Setup UpdatesProxy to always use sys-whonix.
#
# Execute:
# qubesctl state.sls qvm.updates-via-whonix dom0
##


default-update-policy-whonix:
file.prepend:
- name: /etc/qubes-rpc/policy/qubes.UpdatesProxy
- text:
- $type:TemplateVM $default allow,target=sys-whonix
7 changes: 7 additions & 0 deletions qvm/updates-via-whonix.top
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# -*- coding: utf-8 -*-
# vim: set syntax=yaml ts=2 sw=2 sts=2 et :

base:
dom0:
- match: nodegroup
- qvm.updates-via-whonix
2 changes: 2 additions & 0 deletions rpm_spec/qubes-mgmt-salt-dom0-virtual-machines-dom0.spec
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,8 @@ fi
/srv/formulas/base/virtual-machines-formula/qvm/template-whonix-ws.sls
/srv/formulas/base/virtual-machines-formula/qvm/untrusted.sls
/srv/formulas/base/virtual-machines-formula/qvm/untrusted.top
/srv/formulas/base/virtual-machines-formula/qvm/updates-via-whonix.sls
/srv/formulas/base/virtual-machines-formula/qvm/updates-via-whonix.top
/srv/formulas/base/virtual-machines-formula/qvm/vault.sls
/srv/formulas/base/virtual-machines-formula/qvm/vault.top
/srv/formulas/base/virtual-machines-formula/qvm/whonix-ws-dvm.sls
Expand Down

0 comments on commit a0cbb48

Please sign in to comment.