22faf00628
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
Migrate VM puppet agents off the legacy VM puppetmasters and onto the new puppet-on-kubernetes servers, per-wave via hiera and reversible without re-enrolment. Changing server/ca_server alone is insufficient: the agent's ssldir holds a cert signed by the OLD CA that the new CA neither trusts nor recognises. This switches migrated nodes to a FRESH ssldir so the agent generates a new CSR (autosigned on the k8s CA) while the old creds stay on disk for rollback. - Add profiles::puppet::migrate: opt-in (hiera_include) toggle that owns the fresh ssldir directory and documents per-node/per-role/common wiring plus rollback in its class header. - Extend profiles::puppet::client with optional $ssldir and $report_server params (default undef); the ERB template omits both lines when unset, so unmigrated nodes render a byte-identical puppet.conf. - puppet.conf stays owned solely by client.pp's template; migrate.pp adds no competing File resource.
20 lines
545 B
Plaintext
20 lines
545 B
Plaintext
[main]
|
|
dns_alt_names = <%= @dns_alt_names_string %>
|
|
<% unless @ssldir.nil? -%>
|
|
ssldir = <%= @ssldir %>
|
|
<% end -%>
|
|
|
|
[agent]
|
|
server = <%= @server %>
|
|
ca_server = <%= @ca_server %>
|
|
environment = <%= @environment %>
|
|
report = true
|
|
report_server = <%= @report_server.nil? ? @server : @report_server %>
|
|
runinterval = <%= @runinterval %>
|
|
runtimeout = <%= @runtimeout %>
|
|
show_diff = <%= @show_diff %>
|
|
usecacheonfailure = <%= @usecacheonfailure %>
|
|
number_of_facts_soft_limit = <%= @facts_soft_limit %>
|
|
splay = <%= @splay %>
|
|
splaylimit = <%= @splaylimit %>
|