feat: add crypto_policies (#192)

- ensure DEFAULT is used for EL8
- ensure DEFAULT:SHA1 is used for EL9, until issues with crypto are resolved for EL9

Reviewed-on: https://git.query.consul/unkinben/puppet-prod/pulls/192
This commit is contained in:
Ben Vincent 2024-12-08 19:47:59 +11:00
parent b244327c34
commit dbccaea24b
4 changed files with 5 additions and 0 deletions

View File

@ -57,6 +57,7 @@ mod 'stm-file_capability', '6.0.0'
mod 'h0tw1r3-gitea', '3.2.0'
mod 'rehan-mkdir', '2.0.0'
mod 'tailoredautomation-patroni', '2.0.0'
mod 'ssm-crypto_policies', '0.3.3'
mod 'bind',
:git => 'https://git.service.au-syd1.consul/unkinben/puppet-bind.git',

View File

@ -1,5 +1,7 @@
# hieradata/os/AlmaLinux/AlmaLinux8.yaml
---
crypto_policies::policy: 'DEFAULT:SHA1'
profiles::packages::include:
network-scripts: {}

View File

@ -1,5 +1,6 @@
# hieradata/os/AlmaLinux/AlmaLinux9.yaml
---
crypto_policies::policy: 'DEFAULT:SHA1'
profiles::yum::global::repos:
crb:

View File

@ -7,6 +7,7 @@ profiles::puppet::agent::puppet_version: '7.34.0'
hiera_include:
- profiles::almalinux::base
- crypto_policies
profiles::packages::include:
lzo: {}