Give the puppetserver compilers the Vault cert helpers (#482)
profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: #482 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #482.
This commit is contained in:
@@ -64,6 +64,21 @@ configMapGenerator:
|
||||
- resources/compiler/10-auth-conf.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-vault-helpers-seed
|
||||
files:
|
||||
- resources/compiler/20-vault-helpers.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: certmanager-config
|
||||
files:
|
||||
- resources/compiler/certmanager.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: sshsignhost-config
|
||||
files:
|
||||
- resources/compiler/sshsignhost.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: additional-ruby-gems
|
||||
files:
|
||||
- resources/additional-ruby-gems.sh
|
||||
|
||||
Reference in New Issue
Block a user