Install certmanager and sshsignhost from RPM #524

Merged
benvin merged 5 commits from benvin/go-signer-rpms into develop 2026-10-04 15:07:54 +11:00
Member

certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage.

  • Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources
  • Delete the now-unused Python script templates
  • Keep rendering /opt//config.yaml, unchanged ownership and mode
  • Nest certmanager's output_path under vault:, where the binary reads it
  • Drop output_path from sshsignhost's config; the binary has no such key
  • Pin certmanager to 0.2.0 and sshsignhost to 0.1.0 on the puppet master role
  • Point sshsignhost at the sshca mount and signhost role, documented in doc/vault
certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage. - Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources - Delete the now-unused Python script templates - Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode - Nest certmanager's output_path under vault:, where the binary reads it - Drop output_path from sshsignhost's config; the binary has no such key - Pin certmanager to 0.2.0 and sshsignhost to 0.1.0 on the puppet master role - Point sshsignhost at the sshca mount and signhost role, documented in doc/vault
unkin-agent added 1 commit 2026-09-19 15:54:44 +10:00
Install certmanager and sshsignhost from RPM
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
33ae81893c
certmanager and sshsignhost are now Go binaries released as RPMs, and their
packaged paths collide with the venv install these helper classes manage.

- Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources
- Delete the now-unused Python script templates
- Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode
- Nest certmanager's output_path under vault:, where the binary reads it
- Drop output_path from sshsignhost's config; the binary has no such key
- Pin certmanager and sshsignhost to 0.1.0 on the puppet master role
- Point sshsignhost at the sshca mount and signhost role

Depends on certmanager-0.1.0 and sshsignhost-0.1.0 in the rpm-internal repo.
unkin-agent added 1 commit 2026-09-19 16:13:36 +10:00
Pin certmanager to 0.2.0
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ee726e2220
unkin-agent added 2 commits 2026-10-04 15:00:43 +11:00
Merge signer packages into the existing packages include
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was canceled
ci/woodpecker/pr/ruby-check Pipeline was canceled
ebfe626ae6
Author
Member
  • site/profiles/manifests/pki/vault.pp:81 — still execs /usr/local/bin/certmanager (via generate() on the compiler); this PR removes the symlink and the RPM path is not shown → confirm RPM installs there, else point $cmd at the RPM path (same PR); a miss fails catalog compile for every node renewing certs.
  • site/profiles/manifests/ssh/sign.pp:48 — same for /usr/local/bin/sshsignhost → same fix; also confirm the Go binary accepts --valid_principals/--ttl/--public_key/--json (callers unchanged).
  • hieradata/roles/infra/puppet/master.yaml:55 — certmanager output_path stays /tmp/certmanager in hiera, but the body says it is nested under vault: and the template renders it there → no change needed if intended; otherwise drop the key if the binary ignores it.
  • hieradata/roles/infra/puppet/master.yaml:60 — mount/role renamed to sshca/signhost; doc/vault/README.md:92-108 still documents ssh-host-signer/hostrole → update the doc and confirm the sshca mount/signhost role exist in terraform-vault before merge.
  • nit: site/profiles/manifests/puppet/puppetmaster.pp:18 — the packages and the config dirs/files have no ordering (Package -> File[/opt/]) → add require/ordering if the RPM owns /opt/.
- site/profiles/manifests/pki/vault.pp:81 — still execs `/usr/local/bin/certmanager` (via generate() on the compiler); this PR removes the symlink and the RPM path is not shown → confirm RPM installs there, else point `$cmd` at the RPM path (same PR); a miss fails catalog compile for every node renewing certs. - site/profiles/manifests/ssh/sign.pp:48 — same for `/usr/local/bin/sshsignhost` → same fix; also confirm the Go binary accepts `--valid_principals/--ttl/--public_key/--json` (callers unchanged). - hieradata/roles/infra/puppet/master.yaml:55 — certmanager output_path stays `/tmp/certmanager` in hiera, but the body says it is nested under `vault:` and the template renders it there → no change needed if intended; otherwise drop the key if the binary ignores it. - hieradata/roles/infra/puppet/master.yaml:60 — mount/role renamed to `sshca`/`signhost`; doc/vault/README.md:92-108 still documents `ssh-host-signer`/`hostrole` → update the doc and confirm the sshca mount/signhost role exist in terraform-vault before merge. - nit: site/profiles/manifests/puppet/puppetmaster.pp:18 — the packages and the config dirs/files have no ordering (Package -> File[/opt/<tool>]) → add `require`/ordering if the RPM owns /opt/<tool>.
unkin-agent added 1 commit 2026-10-04 15:03:46 +11:00
Document sshca/signhost ssh signing in terraform-vault
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
5fdc308f07
Author
Member

No findings.

No findings.
benvin merged commit 0cfe598f90 into develop 2026-10-04 15:07:54 +11:00
benvin deleted branch benvin/go-signer-rpms 2026-10-04 15:07:54 +11:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/puppet-prod#524