Compare commits

..

8 Commits

Author SHA1 Message Date
unkin-agent 674f51a44b Add consul grpc_tls port and drop drw1 WAN retry join
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
2026-10-07 11:54:31 +11:00
unkin-agent 9d25ba1d9a Enable TLS and mesh gateway WAN federation on consul servers
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
2026-10-07 11:48:29 +11:00
unkin-agent f35b385714 Add consul server federation SANs to consul server certs
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
2026-10-07 11:46:32 +11:00
unkin-agent 2e95cd00d7 Migrate k8s roles to puppet-on-k8s (#545)
Move the k8s roles to the puppet-on-k8s compilers. Their role code (rke2, frrouting, ceph) has no exported resources or PuppetDB queries; the base consul lookup is covered by the static syd1 server list.

- enable profiles::puppet::migrate in the shared roles::infra::k8s hieradata (compute, control, node)

Reviewed-on: #545
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-05 22:10:50 +11:00
unkin-agent 171cf23a93 Migrate incus nodes to puppet-on-k8s (#546)
Incus nodes still run against the VM puppetservers; move them to the k8s compilers as part of the puppet-on-k8s migration.

- enable profiles::puppet::migrate for roles::infra::incus::node

Reviewed-on: #546
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-05 22:03:30 +11:00
unkin-agent 83cb039b97 consul: use static server list for clients (#544)
Hosts compiled on the k8s puppetservers can't see the consul servers in PuppetDB, so the members lookup returns nothing and syd1 clients get no retry_join targets.

- set a static consul server list for syd1 and disable the members lookup there
- keep the PuppetDB members lookup for all other regions

Reviewed-on: #544
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-05 21:33:03 +11:00
unkin-agent fc26d3cc4a nzbget: fix params lookup copied from sonarr (#543)
nzbget defaulted bind_address and port from sonarr::params, which is not loaded on nzbget-only nodes, so catalog compilation failed with "Unknown variable".

- default bind_address/port from nzbget::params

Reviewed-on: #543
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-05 13:36:52 +11:00
unkin-agent 5fe9f7a9da Migrate media roles to puppet-on-k8s (#540)
The ausyd1nxvm2120 canary is healthy on the puppet-on-k8s servers, so move the next role wave across: the media nodes (ausyd1nxvm2045-2051: nzbget, sonarr, radarr, lidarr, readarr, prowlarr, jellyfin).

- enable `profiles::puppet::migrate` in `roles/apps/media.yaml`

Reviewed-on: #540
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-05 12:10:31 +11:00
11 changed files with 41 additions and 5 deletions
@@ -2,6 +2,6 @@
profiles::consul::server::bootstrap_count: 3
profiles::consul::server::raft_multiplier: 10
profiles::consul::server::primary_datacenter: 'au-syd1'
profiles::consul::server::join_remote_regions: true
profiles::consul::server::join_remote_regions: false
profiles::consul::server::remote_regions:
- syd1
+8
View File
@@ -7,3 +7,11 @@ profiles_dns_upstream_forwarder_consul:
- 198.18.19.14
profiles_dns_upstream_forwarder_k8s:
- 198.18.19.20
profiles::consul::client::members_lookup: false
# static: k8s-compiled hosts can't see the servers in PuppetDB; update when servers change
profiles::consul::client::consul_servers:
- ausyd1nxvm2005.main.unkin.net
- ausyd1nxvm2006.main.unkin.net
- ausyd1nxvm2007.main.unkin.net
- ausyd1nxvm2008.main.unkin.net
- ausyd1nxvm2009.main.unkin.net
@@ -20,6 +20,7 @@ profiles::haproxy::mappings:
- 'jellyfin.main.unkin.net be_jellyfin'
- 'fafflix.unkin.net be_jellyfin'
- 'git.unkin.net be_gitea'
- 'grafana.unkin.net be_grafana'
- 'dashboard.ceph.unkin.net be_ceph_dashboard'
- 'mail-webadmin.main.unkin.net be_stalwart_webadmin'
- 'autoconfig.main.unkin.net be_stalwart_webadmin'
@@ -39,6 +40,7 @@ profiles::haproxy::mappings:
- 'jellyfin.main.unkin.net be_jellyfin'
- 'fafflix.unkin.net be_jellyfin'
- 'git.unkin.net be_gitea'
- 'grafana.unkin.net be_grafana'
- 'dashboard.ceph.unkin.net be_ceph_dashboard'
- 'mail-webadmin.main.unkin.net be_stalwart_webadmin'
- 'autoconfig.main.unkin.net be_stalwart_webadmin'
@@ -63,6 +65,7 @@ profiles::haproxy::frontends:
- 'acl_jellyfin req.hdr(host) -i jellyfin.main.unkin.net'
- 'acl_fafflix req.hdr(host) -i fafflix.unkin.net'
- 'acl_gitea req.hdr(host) -i git.unkin.net'
- 'acl_grafana req.hdr(host) -i grafana.unkin.net'
- 'acl_ceph_dashboard req.hdr(host) -i dashboard.ceph.unkin.net'
- 'acl_stalwart_webadmin req.hdr(host) -i mail-webadmin.main.unkin.net'
- 'acl_stalwart_webadmin req.hdr(host) -i autoconfig.main.unkin.net'
@@ -84,6 +87,7 @@ profiles::haproxy::frontends:
- 'set-header X-Frame-Options DENY if acl_jellyfin'
- 'set-header X-Frame-Options DENY if acl_fafflix'
- 'set-header X-Frame-Options DENY if acl_gitea'
- 'set-header X-Frame-Options DENY if acl_grafana'
- 'set-header X-Frame-Options DENY if acl_ceph_dashboard'
- 'set-header X-Frame-Options DENY if acl_stalwart_webadmin'
- 'set-header X-Frame-Options DENY if acl_kanidm'
@@ -399,6 +403,7 @@ profiles::haproxy::certlist::certificates:
- /etc/pki/tls/letsencrypt/nzbget.main.unkin.net/fullchain_combined.pem
- /etc/pki/tls/letsencrypt/fafflix.unkin.net/fullchain_combined.pem
- /etc/pki/tls/letsencrypt/git.unkin.net/fullchain_combined.pem
- /etc/pki/tls/letsencrypt/grafana.unkin.net/fullchain_combined.pem
- /etc/pki/tls/letsencrypt/dashboard.ceph.unkin.net/fullchain_combined.pem
- /etc/pki/tls/letsencrypt/auth.unkin.net/fullchain_combined.pem
- /etc/pki/tls/vault/certificate.pem
@@ -426,5 +431,6 @@ certbot::client::domains:
- nzbget.main.unkin.net
- fafflix.unkin.net
- git.unkin.net
- grafana.unkin.net
- dashboard.ceph.unkin.net
- auth.unkin.net
@@ -2,6 +2,6 @@
profiles::consul::server::bootstrap_count: 3
profiles::consul::server::raft_multiplier: 10
profiles::consul::server::primary_datacenter: 'au-syd1'
profiles::consul::server::join_remote_regions: true
profiles::consul::server::join_remote_regions: false
profiles::consul::server::remote_regions:
- drw1
+2
View File
@@ -2,6 +2,8 @@
hiera_include:
- profiles::nginx::simpleproxy
profiles::puppet::migrate::enabled: true
profiles::yum::global::repos:
ceph:
ensure: present
+2
View File
@@ -14,6 +14,8 @@ hiera_include:
- profiles::storage::cephfsvols
- exporters::frr_exporter
profiles::puppet::migrate::enabled: true
# FIXME: puppet-python wants to try manage python-dev, which is required by the ceph package
python::manage_dev_package: false
+2
View File
@@ -8,6 +8,8 @@ hiera_include:
- frrouting
- rke2
profiles::puppet::migrate::enabled: true
# manage rke2
rke2::bootstrap_node: prodnxsr0001.main.unkin.net
rke2::join_url: https://join-k8s.service.consul:9345
+1
View File
@@ -14,5 +14,6 @@ certbot::domains:
- nzbget.main.unkin.net
- fafflix.unkin.net
- git.unkin.net
- grafana.unkin.net
- dashboard.ceph.unkin.net
- auth.unkin.net
+12
View File
@@ -13,9 +13,19 @@ profiles::consul::server::addresses:
grpc_tls: "%{::networking.ip}"
profiles::consul::server::ports:
grpc: 8502
grpc_tls: 8503
dns: 8600
http: 8500
https: -1
profiles::consul::server::tls:
defaults:
ca_file: /etc/pki/ca-trust/source/anchors/vaultcaroot.pem
cert_file: /etc/pki/tls/vault/full_chain.crt
key_file: /etc/pki/tls/vault/private.key
internal_rpc:
verify_incoming: false
verify_outgoing: false
verify_server_hostname: false
profiles::consul::server::acl:
enabled: true
default_policy: 'deny'
@@ -31,6 +41,8 @@ profiles::pki::vault::alt_names:
- consul.service.consul
- "consul.service.%{facts.country}-%{facts.region}.consul"
- consul
- "server.%{facts.country}-%{facts.region}.consul"
- "%{facts.networking.fqdn}.server.%{facts.country}-%{facts.region}.consul"
# manage a simple nginx reverse proxy
profiles::nginx::simpleproxy::nginx_vhost: 'consul.service.consul'
+2 -2
View File
@@ -6,8 +6,8 @@ class nzbget (
$manage_group = $nzbget::params::manage_group,
$service_enable = $nzbget::params::service_enable,
$service_name = $nzbget::params::service_name,
$bind_address = $sonarr::params::bind_address,
$port = $sonarr::params::port,
$bind_address = $nzbget::params::bind_address,
$port = $nzbget::params::port,
) inherits nzbget::params {
include nzbget::install
+4 -1
View File
@@ -11,6 +11,7 @@ class profiles::consul::server (
Hash $acl = {},
Hash $ports = {},
Hash $addresses = {},
Hash $tls = {},
Boolean $members_lookup = false,
String $members_role = undef,
Array $consul_servers = [],
@@ -112,6 +113,8 @@ class profiles::consul::server (
'acl' => $acl,
'ports' => $ports,
'addresses' => $addresses,
'tls' => $tls,
'auto_reload_config' => true,
'disable_remote_exec' => $disable_remote_exec,
'disable_update_check' => $disable_update_check,
'domain' => $domain,
@@ -129,7 +132,7 @@ class profiles::consul::server (
'advertise_addr' => $advertise_addr,
'retry_join' => $servers_array,
'retry_join_wan' => $remote_servers_array,
'connect' => { 'enabled' => true },
'connect' => { 'enabled' => true, 'enable_mesh_gateway_wan_federation' => true },
'recursors' => ['198.18.19.16'],
},
}