Files
unkinben 0c5684bd9e
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
fix: require openvox-agent instead of puppet-agent in puppet-initial (#172)
## Why

The estate migrated from Puppet to OpenVox. The `puppet-agent` package name no longer exists in the rpm-vendor repos, so kickstart installs of `puppet-initial` fail dependency resolution with "nothing provides puppet-agent", blocking host provisioning.

(Note: `openvox-agent` does `Provides: puppet-agent = 7`, so an alternative root cause is openvox repo priority/availability during the kickstart solve. This PR changes the explicit `Requires` as requested so puppet-initial depends on the package by its real name.)

## Changes

- Change puppet-initial's dependency from `puppet-agent` to `openvox-agent`.
- Bump el8/el9 build version `1.0.4` -> `1.0.5` so a new RPM is published (deploy dedup skips identical filenames).

## Validation

- `make test` — 72 passed.
- Local `nfpm pkg` build in the almalinux9-rpmbuilder image: RPM assembles as `puppet-initial-1.0.5-1.x86_64`, `rpm -qpR` reports `Requires: openvox-agent`.
- Confirmed `openvox-agent` is resolvable from the openvox el9 remote (7.35.0–7.37.2 available).

https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
Reviewed-on: #172
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
2026-08-06 23:25:11 +10:00
..

puppet-initial

A firstrun bootstrap script and oneshot systemd service that initialises a freshly-provisioned host into Puppet:

  1. Sets the FQDN under .main.unkin.net.
  2. Fetches the Puppet CA certificate from the CA service.
  3. Registers the node with a noop agent run against the CA.
  4. Runs the agent a few times against the compile master, then enables the puppet service and disables itself.

Puppet CA endpoint

The CA endpoint defaults to the in-cluster puppetserver CA service puppetca.k8s.syd1.au.unkin.net:8140 (serving the standard /puppet-ca/v1/certificate/ca API).

It is overridable via the environment. The puppet-initial.service unit reads /etc/sysconfig/puppet-initial (EnvironmentFile=-, so the file is optional), which the RPM ships as a commented %config(noreplace) example:

Variable Default Purpose
PUPPETCA_HOST puppetca.k8s.syd1.au.unkin.net CA hostname (CA cert fetch + --server for registration).
PUPPETCA_PORT 8140 CA API port.

Overriding from kickstart

A kickstart %post can point a host at a different CA without rebuilding the RPM by writing the sysconfig file before the service starts:

%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF