Files
puppet-prod/site/profiles/manifests/helpers/certmanager.pp
T
unkin-agent 0cfe598f90 Install certmanager and sshsignhost from RPM (#524)
certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage.

- Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources
- Delete the now-unused Python script templates
- Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode
- Nest certmanager's output_path under vault:, where the binary reads it
- Drop output_path from sshsignhost's config; the binary has no such key
- Pin certmanager to 0.2.0 and sshsignhost to 0.1.0 on the puppet master role
- Point sshsignhost at the sshca mount and signhost role, documented in doc/vault

Reviewed-on: #524
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-04 15:07:54 +11:00

29 lines
816 B
Puppet

# profiles::helpers::certmanager
#
# renders the config.yaml read by the certmanager binary (RPM-installed)
class profiles::helpers::certmanager (
String $script_name = 'certmanager',
Stdlib::AbsolutePath $base_path = "/opt/${script_name}",
Stdlib::AbsolutePath $config_path = "${base_path}/config.yaml",
Hash $vault_config = {},
String $owner = 'root',
String $group = 'root',
){
file { $base_path:
ensure => directory,
mode => '0755',
owner => $owner,
group => $group,
}
file { $config_path:
ensure => file,
mode => '0660',
owner => 'puppet',
group => 'root',
content => Sensitive(template("profiles/helpers/${script_name}_config.yaml.erb")),
require => File[$base_path],
}
}