Compare commits

..

2 Commits

Author SHA1 Message Date
unkin-agent 1ed268acda Add dnsmasq module (#537)
The router runs dnsmasq as a DNS forwarder and DHCP relay from hand-edited config, so its state is not reproducible from code.

- add `dnsmasq` module installing the package, rendering `/etc/dnsmasq.conf` from class params and running the service
- cover listen addresses/interfaces, bind mode, upstream servers, no-resolv, cache-size, domain-needed, bogus-priv, per-domain forwards and dhcp-relay
- add raw `options` lines for anything else
- add `purge_config_dir` (default off) to remove unmanaged `/etc/dnsmasq.d` files

Reviewed-on: #537
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 22:40:46 +10:00
unkin-agent 47e3bdc8f5 Add router role for prodnxsr0020 (#536)
prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq.

- add roles::infra::network::router (base + frrouting + frr_exporter)
- enable ip_forward and disable rp_filter via sysctl::base
- add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160)
- pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP
- listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP
- keep resolv.conf on the local dnsmasq (127.0.0.1)

Reviewed-on: #536
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-03 22:40:01 +10:00
9 changed files with 174 additions and 140 deletions
-2
View File
@@ -178,8 +178,6 @@ lookup_options:
convert_to: Sensitive
stalwart::fallback_admin_password:
convert_to: Sensitive
wireguard::interfaces:
convert_to: Sensitive
facts_path: '/opt/puppetlabs/facter/facts.d'
@@ -0,0 +1,45 @@
---
# primary interface is the WAN uplink; pin host identity to the dum0 loopback
networking_loopback0_ip: 198.18.2.160
networking_loopback1_ip: 198.18.21.160
# dns: keep the local dnsmasq resolver
profiles::dns::base::nameservers:
- 127.0.0.1
profiles::dns::base::search:
- main.unkin.net
profiles::dns::base::primary_interface: dum0
profiles::dns::updater::deny_ranges:
- 198.18.199.0/24
- 198.18.200.0/24
- 10.42.0.0/16
- 10.43.0.0/16
- 10.10.12.0/24 # wg0
- 103.216.190.0/23 # wan uplink
profiles::consul::client::host_addr: "%{hiera('networking_loopback0_ip')}"
# ssh: listen on localhost and dum0 only; knock out the common wan primary ip
lookup_options:
ssh::server::options:
merge:
strategy: deep
knockout_prefix: '--'
ssh::server::options:
ListenAddress:
- "--%{facts.networking.ip}"
- 127.0.0.1
- "%{hiera('networking_loopback0_ip')}"
profiles::ssh::sign::principals:
- "%{hiera('networking_loopback0_ip')}"
# frrouting
frrouting::ospfd_router_id: "%{hiera('networking_loopback0_ip')}"
frrouting::ospfd_interfaces:
dum0:
area: 0.0.0.0
dum1:
area: 0.0.0.0
bond0.201:
area: 0.0.0.0
frrouting::ospf_preferred_source_enable: true
frrouting::ospf_preferred_source: "%{hiera('networking_loopback1_ip')}"
+26
View File
@@ -0,0 +1,26 @@
---
hiera_include:
- frrouting
- exporters::frr_exporter
# routing
sysctl::base::values:
net.ipv4.ip_forward:
value: '1'
net.ipv4.conf.all.rp_filter:
value: '0'
net.ipv4.conf.default.rp_filter:
value: '0'
# frrouting
exporters::frr_exporter::enable: true
frrouting::ospfd_redistribute:
- connected
frrouting::daemons:
ospfd: true
# consul
profiles::consul::client::node_rules:
- resource: service
segment: frr_exporter
disposition: write
+51
View File
@@ -0,0 +1,51 @@
# manage dnsmasq as a dns forwarder and dhcp relay
class dnsmasq (
Boolean $manage_package = true,
Boolean $manage_service = true,
String $package_name = 'dnsmasq',
String $service_name = 'dnsmasq',
Stdlib::Absolutepath $config_file = '/etc/dnsmasq.conf',
Stdlib::Absolutepath $config_dir = '/etc/dnsmasq.d',
Boolean $purge_config_dir = false,
Array[String] $interfaces = [],
Array[Stdlib::IP::Address] $listen_addresses = ['127.0.0.1'],
Enum['bind-interfaces', 'bind-dynamic', 'none'] $bind_mode = 'bind-interfaces',
Boolean $no_resolv = false,
Array[String] $servers = [],
Hash[String, Array[String]] $forwards = {},
Optional[Integer[0]] $cache_size = undef,
Boolean $domain_needed = true,
Boolean $bogus_priv = true,
Array[String] $dhcp_relays = [],
Array[String] $options = [],
) {
if $manage_package {
package { $package_name:
ensure => installed,
before => File[$config_file, $config_dir],
}
}
file { $config_dir:
ensure => directory,
recurse => $purge_config_dir,
purge => $purge_config_dir,
}
file { $config_file:
ensure => file,
owner => 'root',
group => 'root',
mode => '0644',
content => template('dnsmasq/dnsmasq.conf.erb'),
}
if $manage_service {
service { $service_name:
ensure => running,
enable => true,
subscribe => File[$config_file, $config_dir],
}
}
}
@@ -0,0 +1,40 @@
# THIS FILE IS MANAGED BY PUPPET
user=dnsmasq
group=dnsmasq
conf-dir=<%= @config_dir %>,.rpmnew,.rpmsave,.rpmorig
<% @interfaces.each do |iface| -%>
interface=<%= iface %>
<% end -%>
<% unless @listen_addresses.empty? -%>
listen-address=<%= @listen_addresses.join(',') %>
<% end -%>
<% unless @bind_mode == 'none' -%>
<%= @bind_mode %>
<% end -%>
<% if @no_resolv -%>
no-resolv
<% end -%>
<% if @domain_needed -%>
domain-needed
<% end -%>
<% if @bogus_priv -%>
bogus-priv
<% end -%>
<% if @cache_size -%>
cache-size=<%= @cache_size %>
<% end -%>
<% @servers.each do |server| -%>
server=<%= server %>
<% end -%>
<% @forwards.keys.sort.each do |domain| -%>
<% @forwards[domain].each do |server| -%>
server=/<%= domain %>/<%= server %>
<% end -%>
<% end -%>
<% @dhcp_relays.each do |relay| -%>
dhcp-relay=<%= relay %>
<% end -%>
<% @options.each do |line| -%>
<%= line %>
<% end -%>
-44
View File
@@ -1,44 +0,0 @@
# manage wireguard interfaces via wg-quick
class wireguard (
Boolean $manage_package = true,
String $package_name = 'wireguard-tools',
Variant[Hash, Sensitive[Hash]] $interfaces = {},
) {
if $manage_package {
package { $package_name:
ensure => installed,
before => File['/etc/wireguard'],
}
}
file { '/etc/wireguard':
ensure => directory,
owner => 'root',
group => 'root',
mode => '0700',
}
# hiera hands eyaml secrets over as plain strings inside the (Sensitive) hash; re-wrap them per resource
$raw = $interfaces ? {
Sensitive => $interfaces.unwrap,
default => $interfaces,
}
$raw.each |String $iface, Hash $data| {
$peers = $data.get('peers', []).map |Hash $peer| {
$peer['preshared_key'] =~ String ? {
true => $peer + { 'preshared_key' => Sensitive($peer['preshared_key']) },
default => $peer,
}
}
$private_key = $data['private_key'] =~ String ? {
true => Sensitive($data['private_key']),
default => $data['private_key'],
}
wireguard::interface { $iface:
* => $data + { 'peers' => $peers, 'private_key' => $private_key },
}
}
}
-63
View File
@@ -1,63 +0,0 @@
# manage one wg-quick interface; without private_key, /etc/wireguard/<iface>.key is generated once and loaded via PostUp
define wireguard::interface (
Array[Stdlib::IP::Address] $addresses,
Optional[Stdlib::Port] $listen_port = undef,
Optional[Integer[1280, 9000]] $mtu = undef,
Optional[Sensitive[String[1]]] $private_key = undef,
Array[Struct[{
public_key => String[1],
allowed_ips => Variant[String[1], Array[String[1], 1]],
preshared_key => Optional[Sensitive[String[1]]],
endpoint => Optional[String[1]],
persistent_keepalive => Optional[Integer[0, 65535]],
}]] $peers = [],
) {
$conf = "/etc/wireguard/${name}.conf"
$key = $private_key.then |$k| { $k.unwrap }
if $private_key =~ Undef {
$keyfile = "/etc/wireguard/${name}.key"
exec { "wireguard_genkey_${name}":
command => "/bin/sh -c 'umask 077; wg genkey > ${keyfile}'",
creates => $keyfile,
path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'],
require => File['/etc/wireguard'],
}
file { $keyfile:
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
require => Exec["wireguard_genkey_${name}"],
before => [File[$conf], Service["wg-quick@${name}"]],
}
}
file { $conf:
ensure => file,
owner => 'root',
group => 'root',
mode => '0600',
content => Sensitive(template('wireguard/wg.conf.erb')),
show_diff => false,
notify => Exec["wireguard_syncconf_${name}"],
}
service { "wg-quick@${name}":
ensure => running,
enable => true,
require => File[$conf],
}
# syncconf applies peer/key changes without bouncing the tunnel; address/mtu changes need a manual restart
exec { "wireguard_syncconf_${name}":
command => "/bin/bash -c 'wg syncconf ${name} <(wg-quick strip ${name})'",
onlyif => "/usr/sbin/ip link show ${name}",
path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'],
refreshonly => true,
require => Service["wg-quick@${name}"],
}
}
-31
View File
@@ -1,31 +0,0 @@
# THIS FILE IS MANAGED BY PUPPET
[Interface]
<% @addresses.each do |addr| -%>
Address = <%= addr %>
<% end -%>
<% if @listen_port -%>
ListenPort = <%= @listen_port %>
<% end -%>
<% if @mtu -%>
MTU = <%= @mtu %>
<% end -%>
<% if @key -%>
PrivateKey = <%= @key %>
<% else -%>
PostUp = wg set %i private-key /etc/wireguard/%i.key
<% end -%>
<% @peers.each do |peer| -%>
[Peer]
PublicKey = <%= peer['public_key'] %>
<% if peer['preshared_key'] -%>
PresharedKey = <%= peer['preshared_key'].unwrap %>
<% end -%>
AllowedIPs = <%= Array(peer['allowed_ips']).join(', ') %>
<% if peer['endpoint'] -%>
Endpoint = <%= peer['endpoint'] %>
<% end -%>
<% if peer['persistent_keepalive'] -%>
PersistentKeepalive = <%= peer['persistent_keepalive'] %>
<% end -%>
<% end -%>
@@ -0,0 +1,12 @@
# roles::infra::network::router
# an ospf router; frr only, interfaces and firewall are managed outside puppet
#
class roles::infra::network::router {
if $facts['firstrun'] {
include profiles::defaults
include profiles::firstrun::init
}else{
include profiles::defaults
include profiles::base
}
}