#!/bin/bash set -euo pipefail BIN_DIR=/opt/bin CA=/opt/vault-ca-cert.crt if [ ! -s "$CA" ]; then echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2 exit 1 fi # profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin # paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin # lives in the image. Wrappers rather than symlinks because neither binary reads # a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two # processes instead of the puppetserver JVM's own trust store. for bin in certmanager sshsignhost; do if [ ! -x "$BIN_DIR/$bin" ]; then echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2 exit 1 fi cat > "/usr/local/bin/$bin" <