Give the puppetserver compilers the Vault cert helpers (#482)
profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: #482 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #482.
This commit is contained in:
@@ -105,6 +105,17 @@ spec:
|
|||||||
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
||||||
name: compiler-auth-conf-seed
|
name: compiler-auth-conf-seed
|
||||||
subPath: 10-auth-conf.sh
|
subPath: 10-auth-conf.sh
|
||||||
|
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
|
||||||
|
name: compiler-vault-helpers-seed
|
||||||
|
subPath: 20-vault-helpers.sh
|
||||||
|
- mountPath: /opt/certmanager/config.yaml
|
||||||
|
name: certmanager-config
|
||||||
|
subPath: certmanager.yaml
|
||||||
|
readOnly: true
|
||||||
|
- mountPath: /opt/sshsignhost/config.yaml
|
||||||
|
name: sshsignhost-config
|
||||||
|
subPath: sshsignhost.yaml
|
||||||
|
readOnly: true
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: copy-configmaps
|
- name: copy-configmaps
|
||||||
image: busybox:1.35
|
image: busybox:1.35
|
||||||
@@ -202,7 +213,38 @@ spec:
|
|||||||
echo "$EXPECTED encapic" | sha256sum -c -
|
echo "$EXPECTED encapic" | sha256sum -c -
|
||||||
install -m 0755 encapic /opt/bin/encapic
|
install -m 0755 encapic /opt/bin/encapic
|
||||||
|
|
||||||
|
# Puppet shells out to these two from generate() during catalog
|
||||||
|
# compilation: profiles::pki::vault runs certmanager and
|
||||||
|
# profiles::ssh::sign runs sshsignhost.
|
||||||
|
install_release() {
|
||||||
|
name=$1
|
||||||
|
version=$2
|
||||||
|
asset="$name-linux-amd64"
|
||||||
|
base="https://git.unkin.net/unkin/$name/releases/download/$version"
|
||||||
|
curl -fsSL -o "$name" "$base/$asset"
|
||||||
|
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
|
||||||
|
# checksums.txt covers every release asset; pick the line for the
|
||||||
|
# one we downloaded and verify it under our local filename.
|
||||||
|
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
|
||||||
|
if [ -z "$expected" ]; then
|
||||||
|
echo "no checksum for $asset in $version checksums.txt" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "$expected $name" | sha256sum -c -
|
||||||
|
install -m 0755 "$name" "/opt/bin/$name"
|
||||||
|
}
|
||||||
|
|
||||||
|
install_release certmanager v0.2.0
|
||||||
|
install_release sshsignhost v0.1.0
|
||||||
|
|
||||||
echo "Shared binaries setup completed"
|
echo "Shared binaries setup completed"
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 300m
|
||||||
|
memory: 256Mi
|
||||||
|
requests:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- mountPath: /opt/bin/
|
- mountPath: /opt/bin/
|
||||||
name: puppet-shared-bins
|
name: puppet-shared-bins
|
||||||
@@ -247,5 +289,15 @@ spec:
|
|||||||
configMap:
|
configMap:
|
||||||
name: compiler-auth-conf-seed
|
name: compiler-auth-conf-seed
|
||||||
defaultMode: 0755
|
defaultMode: 0755
|
||||||
|
- name: compiler-vault-helpers-seed
|
||||||
|
configMap:
|
||||||
|
name: compiler-vault-helpers-seed
|
||||||
|
defaultMode: 0755
|
||||||
|
- name: certmanager-config
|
||||||
|
configMap:
|
||||||
|
name: certmanager-config
|
||||||
|
- name: sshsignhost-config
|
||||||
|
configMap:
|
||||||
|
name: sshsignhost-config
|
||||||
strategy:
|
strategy:
|
||||||
type: RollingUpdate
|
type: RollingUpdate
|
||||||
|
|||||||
@@ -64,6 +64,21 @@ configMapGenerator:
|
|||||||
- resources/compiler/10-auth-conf.sh
|
- resources/compiler/10-auth-conf.sh
|
||||||
options:
|
options:
|
||||||
disableNameSuffixHash: true
|
disableNameSuffixHash: true
|
||||||
|
- name: compiler-vault-helpers-seed
|
||||||
|
files:
|
||||||
|
- resources/compiler/20-vault-helpers.sh
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: certmanager-config
|
||||||
|
files:
|
||||||
|
- resources/compiler/certmanager.yaml
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
|
- name: sshsignhost-config
|
||||||
|
files:
|
||||||
|
- resources/compiler/sshsignhost.yaml
|
||||||
|
options:
|
||||||
|
disableNameSuffixHash: true
|
||||||
- name: additional-ruby-gems
|
- name: additional-ruby-gems
|
||||||
files:
|
files:
|
||||||
- resources/additional-ruby-gems.sh
|
- resources/additional-ruby-gems.sh
|
||||||
|
|||||||
+29
@@ -0,0 +1,29 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
BIN_DIR=/opt/bin
|
||||||
|
CA=/opt/vault-ca-cert.crt
|
||||||
|
|
||||||
|
if [ ! -s "$CA" ]; then
|
||||||
|
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
||||||
|
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
||||||
|
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
||||||
|
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
||||||
|
# processes instead of the puppetserver JVM's own trust store.
|
||||||
|
for bin in certmanager sshsignhost; do
|
||||||
|
if [ ! -x "$BIN_DIR/$bin" ]; then
|
||||||
|
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
cat > "/usr/local/bin/$bin" <<WRAPPER
|
||||||
|
#!/bin/sh
|
||||||
|
SSL_CERT_FILE=$CA
|
||||||
|
export SSL_CERT_FILE
|
||||||
|
exec $BIN_DIR/$bin "\$@"
|
||||||
|
WRAPPER
|
||||||
|
chmod 0755 "/usr/local/bin/$bin"
|
||||||
|
done
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
vault:
|
||||||
|
addr: https://vault.service.consul:8200
|
||||||
|
auth_method: kubernetes
|
||||||
|
k8s_mount: k8s/au/syd1
|
||||||
|
k8s_role: puppet_certmanager
|
||||||
|
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
mount_point: pki_int
|
||||||
|
role_name: servers_default
|
||||||
|
output_path: /tmp/certmanager
|
||||||
|
tls_skip_verify: false
|
||||||
|
timeout: 30s
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
vault:
|
||||||
|
addr: https://vault.service.consul:8200
|
||||||
|
auth_method: kubernetes
|
||||||
|
k8s_mount: k8s/au/syd1
|
||||||
|
k8s_role: puppet_sshsigner
|
||||||
|
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
mount_point: sshca
|
||||||
|
role_name: signhost
|
||||||
|
tls_skip_verify: false
|
||||||
|
timeout: 30s
|
||||||
Reference in New Issue
Block a user