Add pdbmux: a merging PuppetDB proxy for the VM->k8s migration
During the VM->k8s Puppet migration there are two PuppetDBs - the legacy Consul-registered one (http://puppetdbapi.service.consul:8080) and the new k8s one (https://puppetdb.k8s.syd1.au.unkin.net) - and nodes move between them as they migrate. node-lookup and pblastreport need a single, consistent merged view without knowing which PuppetDB a node currently lives in. This adds pdbmux, a small HTTP daemon that fronts both backends: - Adds cmd/pdbmux/ (config.go, merge.go, server.go, main.go): a cobra tool whose default action (also `serve`) starts the proxy, plus config init/show and version subcommands, following the repo's config precedence pattern (defaults < config file < env PDBMUX_* < flags). - Merges GET /pdb/query/v4/nodes: dedupes by certname, keeping the record with the newer report_timestamp. - Merges GET /pdb/query/v4/facts at node granularity: keeps all facts from the backend owning each certname, chosen by the freshness strategy (per-certname report_timestamp map from /nodes, cached for freshness_ttl) or a static prefer-backend fallback. - Fans out to both backends concurrently, serves the survivor if one fails, and returns 502 only when both fail; passes records through as raw JSON so unknown fields survive. - Transparently proxies any other /pdb/query/v4/* path to the configurable primary, and exposes /healthz with per-backend reachability (200 ok / 200 degraded / 503 down). - Adds table-driven tests (go test -race, no network) covering merge logic, handler behaviour with httptest backends, query passthrough, one/both backend down, and config precedence/validation. - Wires pdbmux into the build/release: Makefile BINARIES, scripts/build-rpm.sh, nfpm packaging (binary + completions + a systemd unit), and the release pipeline's cross-platform build + Gitea asset list. - Documents pdbmux (what/why/endpoints/merge-semantics/config/deployment) in a new README.md and updates AGENTS.md.
This commit is contained in:
@@ -42,6 +42,18 @@ contents:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
- src: dist/pdbmux
|
||||
dst: /usr/bin/pdbmux
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
# systemd unit for the pdbmux proxy daemon (config: /etc/pdbmux/config.yaml).
|
||||
- src: packaging/pdbmux.service
|
||||
dst: /usr/lib/systemd/system/pdbmux.service
|
||||
file_info:
|
||||
mode: 0644
|
||||
|
||||
# Shell completions (generated by scripts/build-rpm.sh before packaging).
|
||||
- src: dist/completions/node-lookup.bash
|
||||
@@ -80,3 +92,15 @@ contents:
|
||||
dst: /usr/share/fish/vendor_completions.d/pblastreport.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
- src: dist/completions/pdbmux.bash
|
||||
dst: /usr/share/bash-completion/completions/pdbmux
|
||||
file_info:
|
||||
mode: 0644
|
||||
- src: dist/completions/_pdbmux
|
||||
dst: /usr/share/zsh/site-functions/_pdbmux
|
||||
file_info:
|
||||
mode: 0644
|
||||
- src: dist/completions/pdbmux.fish
|
||||
dst: /usr/share/fish/vendor_completions.d/pdbmux.fish
|
||||
file_info:
|
||||
mode: 0644
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
[Unit]
|
||||
Description=pdbmux - merging proxy over old + new PuppetDB during migration
|
||||
Documentation=https://git.unkin.net/unkin/node-lookup
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
# Configure via /etc/pdbmux/config.yaml or PDBMUX_* env in this file / a drop-in.
|
||||
# Example env overrides:
|
||||
# Environment=PDBMUX_LISTEN=:8080
|
||||
# Environment=PDBMUX_MERGE=freshness
|
||||
Environment=XDG_CONFIG_HOME=/etc
|
||||
ExecStart=/usr/bin/pdbmux serve
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
# Hardening: pdbmux only makes outbound HTTP(S) and listens on a socket.
|
||||
DynamicUser=yes
|
||||
NoNewPrivileges=yes
|
||||
ProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
PrivateTmp=yes
|
||||
PrivateDevices=yes
|
||||
ProtectKernelTunables=yes
|
||||
ProtectControlGroups=yes
|
||||
RestrictAddressFamilies=AF_INET AF_INET6
|
||||
RestrictNamespaces=yes
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user