os/Fedora: add Fedora 44 support for the base role (#497)
## Why
We want to manage Fedora 44 hosts with this Puppet codebase, starting with the `base` role only. Fedora reuses the RedHat osfamily code paths (dnf/yum, crypto-policies, firewalld, openvox), so this adds the Fedora-specific hieradata, repositories, and gates needed for `base` to compile and apply, mirroring how AlmaLinux is wired and consuming the artifactapi `rpm-internal-f<major>` / `rpm-vendor-f<major>` local repos. Everything is keyed off `facts.os.release.major` so a future Fedora release only needs its artifactapi local repos created, not new hieradata.
## How
- Add `hieradata/os/Fedora/all_releases.yaml`:
- Define dnf repos via `profiles::yum::global::repos`: `fedora` and `updates` proxied through artifactapi's `fedora` remote, plus the artifactapi locals `rpm-internal-f%{major}` and `rpm-vendor-f%{major}`; GPG via the on-disk `fedora-gpg-keys`; metalink/mirrorlist cleared so only the artifactapi baseurl is used.
- Set `crypto_policies::policy: DEFAULT`, `profiles::puppet::agent::openvox_enable: true`, and `lm-sensors:📦 lm_sensors`.
- Fix up the base package set for Fedora: exclude `p7zip`/`dstat`/`iotop` (absent on Fedora) and include `7zip` and `iotop-c`, plus the same `crypto-policies-scripts`/`lzo`/`policycoreutils`/`unar`/`xz` additions AlmaLinux carries.
- Wire `profiles::fedora::base` via `hiera_include`.
- Add `profiles::fedora::base` (ensures NetworkManager enabled) as the Fedora analogue of `profiles::almalinux::base`; deliberately minimal so it can grow into workstation/laptop use later.
- Make `profiles::puppet::agent` select the OpenVox distribution path (`fedora/<major>` on Fedora, `el/<major>` elsewhere); AlmaLinux/Debian behaviour is unchanged.
## Validation
`puppet-lint`, puppet manifest validate, and `yamllint` all pass via the repo's pre-commit hooks on the changed files.
## Note for reviewer
OpenVox does not yet publish a Fedora 44 build (`openvox7/fedora/` currently has only 36/40/41), so `openvox-agent` will 404 until upstream publishes f44 or a build is placed in `rpm-internal-f44`. The Puppet code produces the correct path for when that exists; installing the agent is a prerequisite for a Fedora 44 host to actually run.
https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
Reviewed-on: #497
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #497.
This commit is contained in:
@@ -0,0 +1,69 @@
|
||||
# hieradata/os/Fedora/all_releases.yaml
|
||||
---
|
||||
# Fedora reuses the RedHat osfamily code paths (dnf/yum, crypto-policies,
|
||||
# firewalld, openvox). Everything here keys off facts.os.release.major so a
|
||||
# future Fedora release only needs its artifactapi local repos created, not new
|
||||
# hieradata.
|
||||
|
||||
# crypto-policies: use the distro default. Kept here (not per-release) so newer
|
||||
# Fedora releases inherit it for free.
|
||||
crypto_policies::policy: 'DEFAULT'
|
||||
|
||||
# Puppet agent via OpenVox. RedHat-family builds for Fedora live under
|
||||
# openvox7/fedora/<major> (see profiles::puppet::agent).
|
||||
profiles::puppet::agent::openvox_enable: true
|
||||
|
||||
lm-sensors::package: lm_sensors
|
||||
|
||||
# Fedora-specific base setup (NetworkManager, future workstation/laptop hooks).
|
||||
hiera_include:
|
||||
- profiles::fedora::base
|
||||
|
||||
# Base package set adjustments for Fedora:
|
||||
# - p7zip was dropped from Fedora; the real 7-Zip ships as "7zip"
|
||||
# - dstat was removed from Fedora with no drop-in successor in the base set
|
||||
# - iotop is provided by the C rewrite package "iotop-c"
|
||||
profiles::packages::exclude:
|
||||
- p7zip
|
||||
- dstat
|
||||
- iotop
|
||||
profiles::packages::include:
|
||||
7zip: {}
|
||||
iotop-c: {}
|
||||
crypto-policies-scripts: {}
|
||||
lzo: {}
|
||||
policycoreutils: {}
|
||||
unar: {}
|
||||
xz: {}
|
||||
|
||||
profiles::yum::global::repos:
|
||||
fedora:
|
||||
name: fedora
|
||||
descr: Fedora %{facts.os.release.major} - %{facts.os.architecture}
|
||||
target: /etc/yum.repos.d/fedora.repo
|
||||
baseurl: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/fedora/releases/%{facts.os.release.major}/Everything/%{facts.os.architecture}/os/
|
||||
gpgkey: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-%{facts.os.release.major}-%{facts.os.architecture}
|
||||
metalink: absent
|
||||
mirrorlist: absent
|
||||
updates:
|
||||
name: updates
|
||||
descr: Fedora %{facts.os.release.major} - %{facts.os.architecture} - Updates
|
||||
target: /etc/yum.repos.d/fedora-updates.repo
|
||||
baseurl: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/fedora/updates/%{facts.os.release.major}/Everything/%{facts.os.architecture}/
|
||||
gpgkey: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-%{facts.os.release.major}-%{facts.os.architecture}
|
||||
metalink: absent
|
||||
mirrorlist: absent
|
||||
rpm-internal:
|
||||
name: rpm-internal-f%{facts.os.release.major}
|
||||
descr: rpm-internal-f%{facts.os.release.major} repository
|
||||
target: /etc/yum.repos.d/rpm-internal.repo
|
||||
baseurl: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/local/rpm-internal-f%{facts.os.release.major}/
|
||||
gpgcheck: false
|
||||
mirrorlist: absent
|
||||
rpm-vendor:
|
||||
name: rpm-vendor-f%{facts.os.release.major}
|
||||
descr: rpm-vendor-f%{facts.os.release.major} repository
|
||||
target: /etc/yum.repos.d/rpm-vendor.repo
|
||||
baseurl: https://artifactapi.k8s.syd1.au.unkin.net/api/v1/local/rpm-vendor-f%{facts.os.release.major}/
|
||||
gpgcheck: false
|
||||
mirrorlist: absent
|
||||
@@ -0,0 +1,14 @@
|
||||
# base fedora settings
|
||||
#
|
||||
# Fedora hosts share the RedHat-family base profiles (yum/dnf, crypto-policies,
|
||||
# firewalld); this class carries the handful of Fedora-specific bits. Kept
|
||||
# deliberately small so it can grow into workstation/laptop (e.g. sway) support
|
||||
# later without disturbing servers.
|
||||
class profiles::fedora::base {
|
||||
# Fedora manages interfaces through NetworkManager. Ensure it is enabled and
|
||||
# running (some minimal and cloud images ship it disabled).
|
||||
service { 'NetworkManager':
|
||||
ensure => running,
|
||||
enable => true,
|
||||
}
|
||||
}
|
||||
@@ -16,11 +16,18 @@ class profiles::puppet::agent (
|
||||
$use_service = 'puppet'
|
||||
}
|
||||
|
||||
# OpenVox publishes RedHat-family builds per distribution: enterprise-linux
|
||||
# under el/<major>, Fedora under fedora/<major>.
|
||||
$openvox_dist = $facts['os']['name'] ? {
|
||||
'Fedora' => 'fedora',
|
||||
default => 'el',
|
||||
}
|
||||
|
||||
# manage the yumrepo for the given package
|
||||
if $openvox_enable and $facts['os']['family'] == 'RedHat' {
|
||||
yumrepo { 'openvox':
|
||||
ensure => 'present',
|
||||
baseurl => "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/openvox/openvox7/el/${facts['os']['release']['major']}/${facts['os']['architecture']}/",
|
||||
baseurl => "https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/openvox/openvox7/${openvox_dist}/${facts['os']['release']['major']}/${facts['os']['architecture']}/",
|
||||
descr => 'openvox repository',
|
||||
gpgkey => 'https://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/openvox/GPG-KEY-openvox.pub',
|
||||
notify => Exec['dnf_makecache'],
|
||||
|
||||
Reference in New Issue
Block a user