From fe51aa07beb451d8c99d7eb0732c9d9ffa57d2cd Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Thu, 24 Sep 2026 21:15:09 +1000 Subject: [PATCH] Give the puppetserver compilers the Vault cert helpers (#482) profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/482 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- .../deployment_puppetserver-compiler.yaml | 52 +++++++++++++++++++ apps/base/puppet/kustomization.yaml | 15 ++++++ .../resources/compiler/20-vault-helpers.sh | 29 +++++++++++ .../resources/compiler/certmanager.yaml | 12 +++++ .../resources/compiler/sshsignhost.yaml | 11 ++++ 5 files changed, 119 insertions(+) create mode 100755 apps/base/puppet/resources/compiler/20-vault-helpers.sh create mode 100644 apps/base/puppet/resources/compiler/certmanager.yaml create mode 100644 apps/base/puppet/resources/compiler/sshsignhost.yaml diff --git a/apps/base/puppet/deployment_puppetserver-compiler.yaml b/apps/base/puppet/deployment_puppetserver-compiler.yaml index 60afefe..dca31d8 100644 --- a/apps/base/puppet/deployment_puppetserver-compiler.yaml +++ b/apps/base/puppet/deployment_puppetserver-compiler.yaml @@ -105,6 +105,17 @@ spec: - mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh name: compiler-auth-conf-seed subPath: 10-auth-conf.sh + - mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh + name: compiler-vault-helpers-seed + subPath: 20-vault-helpers.sh + - mountPath: /opt/certmanager/config.yaml + name: certmanager-config + subPath: certmanager.yaml + readOnly: true + - mountPath: /opt/sshsignhost/config.yaml + name: sshsignhost-config + subPath: sshsignhost.yaml + readOnly: true initContainers: - name: copy-configmaps image: busybox:1.35 @@ -202,7 +213,38 @@ spec: echo "$EXPECTED encapic" | sha256sum -c - install -m 0755 encapic /opt/bin/encapic + # Puppet shells out to these two from generate() during catalog + # compilation: profiles::pki::vault runs certmanager and + # profiles::ssh::sign runs sshsignhost. + install_release() { + name=$1 + version=$2 + asset="$name-linux-amd64" + base="https://git.unkin.net/unkin/$name/releases/download/$version" + curl -fsSL -o "$name" "$base/$asset" + curl -fsSL -o "$name.checksums" "$base/checksums.txt" + # checksums.txt covers every release asset; pick the line for the + # one we downloaded and verify it under our local filename. + expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums") + if [ -z "$expected" ]; then + echo "no checksum for $asset in $version checksums.txt" >&2 + exit 1 + fi + echo "$expected $name" | sha256sum -c - + install -m 0755 "$name" "/opt/bin/$name" + } + + install_release certmanager v0.2.0 + install_release sshsignhost v0.1.0 + echo "Shared binaries setup completed" + resources: + limits: + cpu: 300m + memory: 256Mi + requests: + cpu: 100m + memory: 64Mi volumeMounts: - mountPath: /opt/bin/ name: puppet-shared-bins @@ -247,5 +289,15 @@ spec: configMap: name: compiler-auth-conf-seed defaultMode: 0755 + - name: compiler-vault-helpers-seed + configMap: + name: compiler-vault-helpers-seed + defaultMode: 0755 + - name: certmanager-config + configMap: + name: certmanager-config + - name: sshsignhost-config + configMap: + name: sshsignhost-config strategy: type: RollingUpdate diff --git a/apps/base/puppet/kustomization.yaml b/apps/base/puppet/kustomization.yaml index a09582e..017f512 100644 --- a/apps/base/puppet/kustomization.yaml +++ b/apps/base/puppet/kustomization.yaml @@ -64,6 +64,21 @@ configMapGenerator: - resources/compiler/10-auth-conf.sh options: disableNameSuffixHash: true + - name: compiler-vault-helpers-seed + files: + - resources/compiler/20-vault-helpers.sh + options: + disableNameSuffixHash: true + - name: certmanager-config + files: + - resources/compiler/certmanager.yaml + options: + disableNameSuffixHash: true + - name: sshsignhost-config + files: + - resources/compiler/sshsignhost.yaml + options: + disableNameSuffixHash: true - name: additional-ruby-gems files: - resources/additional-ruby-gems.sh diff --git a/apps/base/puppet/resources/compiler/20-vault-helpers.sh b/apps/base/puppet/resources/compiler/20-vault-helpers.sh new file mode 100755 index 0000000..cab9dfa --- /dev/null +++ b/apps/base/puppet/resources/compiler/20-vault-helpers.sh @@ -0,0 +1,29 @@ +#!/bin/bash +set -euo pipefail + +BIN_DIR=/opt/bin +CA=/opt/vault-ca-cert.crt + +if [ ! -s "$CA" ]; then + echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2 + exit 1 +fi + +# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin +# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin +# lives in the image. Wrappers rather than symlinks because neither binary reads +# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two +# processes instead of the puppetserver JVM's own trust store. +for bin in certmanager sshsignhost; do + if [ ! -x "$BIN_DIR/$bin" ]; then + echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2 + exit 1 + fi + cat > "/usr/local/bin/$bin" <