0cfe598f90
certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage. - Drop the pyvenv, pip, rendered script and /usr/local/bin symlink resources - Delete the now-unused Python script templates - Keep rendering /opt/<tool>/config.yaml, unchanged ownership and mode - Nest certmanager's output_path under vault:, where the binary reads it - Drop output_path from sshsignhost's config; the binary has no such key - Pin certmanager to 0.2.0 and sshsignhost to 0.1.0 on the puppet master role - Point sshsignhost at the sshca mount and signhost role, documented in doc/vault Reviewed-on: #524 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
29 lines
816 B
Puppet
29 lines
816 B
Puppet
# profiles::helpers::certmanager
|
|
#
|
|
# renders the config.yaml read by the certmanager binary (RPM-installed)
|
|
class profiles::helpers::certmanager (
|
|
String $script_name = 'certmanager',
|
|
Stdlib::AbsolutePath $base_path = "/opt/${script_name}",
|
|
Stdlib::AbsolutePath $config_path = "${base_path}/config.yaml",
|
|
Hash $vault_config = {},
|
|
String $owner = 'root',
|
|
String $group = 'root',
|
|
){
|
|
|
|
file { $base_path:
|
|
ensure => directory,
|
|
mode => '0755',
|
|
owner => $owner,
|
|
group => $group,
|
|
}
|
|
|
|
file { $config_path:
|
|
ensure => file,
|
|
mode => '0660',
|
|
owner => 'puppet',
|
|
group => 'root',
|
|
content => Sensitive(template("profiles/helpers/${script_name}_config.yaml.erb")),
|
|
require => File[$base_path],
|
|
}
|
|
}
|