Some urgent security updates on deployed workstations (e.g., RPC policy changes) may need to be applied via provisioning logic that is managed via Salt. As an interim solution, we've agreed that it makes sense to enforce the dom0 salt state as part of the preflight updater merged in #396. This will add some time to the preflight update process; as before/after comparison, it would be good to stopwatch this added time as part of the review process.