Install certmanager and sshsignhost from RPM
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful

certmanager and sshsignhost are now Go binaries released as RPMs, and their
packaged paths collide with the venv install these helper classes manage.

- Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources
- Delete the now-unused Python script templates
- Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode
- Nest certmanager's output_path under vault:, where the binary reads it
- Drop output_path from sshsignhost's config; the binary has no such key
- Pin certmanager and sshsignhost to 0.1.0 on the puppet master role
- Point sshsignhost at the sshca mount and signhost role

Depends on certmanager-0.1.0 and sshsignhost-0.1.0 in the rpm-internal repo.
This commit is contained in:
2026-09-19 15:54:23 +10:00
parent 979c188c34
commit 33ae81893c
7 changed files with 38 additions and 316 deletions
+9 -3
View File
@@ -47,12 +47,18 @@ profiles::helpers::certmanager::vault_config:
profiles::helpers::sshsignhost::vault_config:
addr: 'https://vault.service.consul:8200'
mount_point: 'ssh-host-signer'
mount_point: 'sshca'
approle_path: 'approle'
role_name: 'hostrole'
output_path: '/tmp/sshsignhost'
role_name: 'signhost'
role_id: "%{lookup('sshsignhost::role_id')}"
# Vault signing helpers, delivered as RPMs from the rpm-internal repo.
profiles::packages::include:
certmanager:
ensure: '0.1.0'
sshsignhost:
ensure: '0.1.0'
profiles::puppet::server::agent_server: 'puppet.query.consul'
profiles::puppet::server::report_server: 'puppet.query.consul'
profiles::puppet::server::ca_server: 'puppetca.query.consul'