# puppet-initial A firstrun bootstrap script and oneshot systemd service that initialises a freshly-provisioned host into Puppet: 1. Sets the FQDN under `.main.unkin.net`. 2. Fetches the Puppet CA certificate from the CA service. 3. Registers the node with a noop agent run against the CA. 4. Runs the agent a few times against the compile master, then enables the `puppet` service and disables itself. ## Puppet CA endpoint The CA endpoint defaults to the in-cluster puppetserver CA service `puppetca.k8s.syd1.au.unkin.net:8140` (serving the standard `/puppet-ca/v1/certificate/ca` API). It is overridable via the environment. The `puppet-initial.service` unit reads `/etc/sysconfig/puppet-initial` (`EnvironmentFile=-`, so the file is optional), which the RPM ships as a commented `%config(noreplace)` example: | Variable | Default | Purpose | |-----------------|----------------------------------|-------------------------------------------------------------| | `PUPPETCA_HOST` | `puppetca.k8s.syd1.au.unkin.net` | CA hostname (CA cert fetch + `--server` for registration). | | `PUPPETCA_PORT` | `8140` | CA API port. | ### Overriding from kickstart A kickstart `%post` can point a host at a different CA without rebuilding the RPM by writing the sysconfig file before the service starts: ```bash %post cat > /etc/sysconfig/puppet-initial <<'EOF' PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net PUPPETCA_PORT=8140 EOF ```