fe51aa07be
profiles::pki::vault and profiles::ssh::sign shell out to /usr/local/bin/certmanager and /usr/local/bin/sshsignhost from generate() during catalog compilation. Neither binary exists in the compiler image, so every node using them fails to compile. - install certmanager v0.2.0 and sshsignhost v0.1.0 onto the shared bin volume with sha256 verification - wrap both at /usr/local/bin from a pre-default entrypoint hook, failing startup loudly if either is missing - mount read-only Vault configs for both: kubernetes auth on k8s/au/syd1, internal CA verified rather than skipped Reviewed-on: #482 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
30 lines
930 B
Bash
Executable File
30 lines
930 B
Bash
Executable File
#!/bin/bash
|
|
set -euo pipefail
|
|
|
|
BIN_DIR=/opt/bin
|
|
CA=/opt/vault-ca-cert.crt
|
|
|
|
if [ ! -s "$CA" ]; then
|
|
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
|
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
|
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
|
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
|
# processes instead of the puppetserver JVM's own trust store.
|
|
for bin in certmanager sshsignhost; do
|
|
if [ ! -x "$BIN_DIR/$bin" ]; then
|
|
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
|
exit 1
|
|
fi
|
|
cat > "/usr/local/bin/$bin" <<WRAPPER
|
|
#!/bin/sh
|
|
SSL_CERT_FILE=$CA
|
|
export SSL_CERT_FILE
|
|
exec $BIN_DIR/$bin "\$@"
|
|
WRAPPER
|
|
chmod 0755 "/usr/local/bin/$bin"
|
|
done
|