feat: make puppet-initial CA endpoint configurable, default to k8s puppetca
ci/woodpecker/pr/build-fedora42 Pipeline was successful
ci/woodpecker/pr/build-fedora44 Pipeline was successful
ci/woodpecker/pr/build-fedora43 Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline was successful

The puppet-initial firstrun bootstrap hardcoded the legacy Consul CA
endpoint puppetca.query.consul:8140. That VM-era CA is being replaced by
the in-cluster puppetserver CA service.

- Default the CA host to puppetca.k8s.syd1.au.unkin.net (still :8140,
  same /puppet-ca/v1/certificate/ca API; verified serving HTTP 200).
- Read PUPPETCA_HOST / PUPPETCA_PORT from the environment so a host can
  be pointed at a different CA without rebuilding the RPM.
- Wire the env through systemd via EnvironmentFile=-/etc/sysconfig/puppet-initial
  and ship a commented %config(noreplace) example at that path, so a
  kickstart %post can override per-host.
- Document the override (incl. a kickstart %post example) in a new README.
- Bump el8/el9 build version 1.0.3 -> 1.0.4 so a new RPM is published.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
Ben Vincent
2026-07-28 22:01:10 +10:00
parent 3ba9f77c10
commit 57a472d24e
6 changed files with 70 additions and 4 deletions
+38
View File
@@ -0,0 +1,38 @@
# puppet-initial
A firstrun bootstrap script and oneshot systemd service that initialises a
freshly-provisioned host into Puppet:
1. Sets the FQDN under `.main.unkin.net`.
2. Fetches the Puppet CA certificate from the CA service.
3. Registers the node with a noop agent run against the CA.
4. Runs the agent a few times against the compile master, then enables the
`puppet` service and disables itself.
## Puppet CA endpoint
The CA endpoint defaults to the in-cluster puppetserver CA service
`puppetca.k8s.syd1.au.unkin.net:8140` (serving the standard
`/puppet-ca/v1/certificate/ca` API).
It is overridable via the environment. The `puppet-initial.service` unit reads
`/etc/sysconfig/puppet-initial` (`EnvironmentFile=-`, so the file is optional),
which the RPM ships as a commented `%config(noreplace)` example:
| Variable | Default | Purpose |
|-----------------|----------------------------------|-------------------------------------------------------------|
| `PUPPETCA_HOST` | `puppetca.k8s.syd1.au.unkin.net` | CA hostname (CA cert fetch + `--server` for registration). |
| `PUPPETCA_PORT` | `8140` | CA API port. |
### Overriding from kickstart
A kickstart `%post` can point a host at a different CA without rebuilding the
RPM by writing the sysconfig file before the service starts:
```bash
%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF
```
+2 -2
View File
@@ -11,9 +11,9 @@ builds:
release: '1'
repository:
- almalinux/el8
version: 1.0.3
version: 1.0.4
- image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
release: '1'
repository:
- almalinux/el9
version: 1.0.3
version: 1.0.4
+7
View File
@@ -31,6 +31,13 @@ contents:
mode: 0644
owner: root
group: root
- src: /app/resources/puppet-initial.sysconfig
dst: /etc/sysconfig/puppet-initial
type: config|noreplace
file_info:
mode: 0644
owner: root
group: root
# Scripts to run during installation/removal (optional)
scripts:
+9 -2
View File
@@ -1,14 +1,21 @@
#!/bin/bash
# Puppet CA endpoint. Overridable via the environment (systemd reads
# /etc/sysconfig/puppet-initial via EnvironmentFile), so kickstart %post can
# point a host at a different CA without rebuilding the RPM. Defaults to the
# in-cluster puppetserver CA service.
PUPPETCA_HOST="${PUPPETCA_HOST:-puppetca.k8s.syd1.au.unkin.net}"
PUPPETCA_PORT="${PUPPETCA_PORT:-8140}"
# Ensure the hostname is set
hostnamectl set-hostname $(hostname -s).main.unkin.net
grep '^HOSTNAME=' /etc/sysconfig/network | cut -d= -f2 | grep -q '\.' || sed -i 's/^\(HOSTNAME=[^\.]*\)$/\1.main.unkin.net/' /etc/sysconfig/network
# Install CA for Puppet
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate https://puppetca.query.consul:8140/puppet-ca/v1/certificate/ca -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
test -f /etc/puppetlabs/puppet/ssl/certs/ca.pem || mkdir -p /etc/puppetlabs/puppet/ssl/certs && wget --no-check-certificate "https://${PUPPETCA_HOST}:${PUPPETCA_PORT}/puppet-ca/v1/certificate/ca" -O /etc/puppetlabs/puppet/ssl/certs/ca.pem
# Registering to Puppet server
/opt/puppetlabs/bin/puppet agent --test --server puppetca.query.consul --noop --onetime --no-daemonize --verbose
/opt/puppetlabs/bin/puppet agent --test --server "${PUPPETCA_HOST}" --noop --onetime --no-daemonize --verbose
# Running Puppet agent five times with a 30-second gap between each run, stop puppet service at the end of each run
for i in {1..5}; do
@@ -5,6 +5,7 @@ Wants=network-online.target
[Service]
Type=simple
EnvironmentFile=-/etc/sysconfig/puppet-initial
ExecStart=/usr/local/bin/puppet-initial
RemainAfterExit=true
ExecStop=/bin/true
@@ -0,0 +1,13 @@
# Environment overrides for the puppet-initial firstrun bootstrap.
# Read by the puppet-initial.service unit (EnvironmentFile=-/etc/sysconfig/puppet-initial).
# A kickstart %post can write this file to point a host at a different Puppet CA
# without rebuilding the RPM. All values are optional; the defaults below match
# the shipped in-cluster puppetserver CA service.
# Hostname of the Puppet CA service. Used both to fetch the CA certificate
# (https://<host>:<port>/puppet-ca/v1/certificate/ca) and as --server for the
# initial noop agent registration run.
#PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
# Port the Puppet CA API listens on.
#PUPPETCA_PORT=8140