0c5684bd9e
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
## Why The estate migrated from Puppet to OpenVox. The `puppet-agent` package name no longer exists in the rpm-vendor repos, so kickstart installs of `puppet-initial` fail dependency resolution with "nothing provides puppet-agent", blocking host provisioning. (Note: `openvox-agent` does `Provides: puppet-agent = 7`, so an alternative root cause is openvox repo priority/availability during the kickstart solve. This PR changes the explicit `Requires` as requested so puppet-initial depends on the package by its real name.) ## Changes - Change puppet-initial's dependency from `puppet-agent` to `openvox-agent`. - Bump el8/el9 build version `1.0.4` -> `1.0.5` so a new RPM is published (deploy dedup skips identical filenames). ## Validation - `make test` — 72 passed. - Local `nfpm pkg` build in the almalinux9-rpmbuilder image: RPM assembles as `puppet-initial-1.0.5-1.x86_64`, `rpm -qpR` reports `Requires: openvox-agent`. - Confirmed `openvox-agent` is resolvable from the openvox el9 remote (7.35.0–7.37.2 available). https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT Reviewed-on: #172 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
puppet-initial
A firstrun bootstrap script and oneshot systemd service that initialises a freshly-provisioned host into Puppet:
- Sets the FQDN under
.main.unkin.net. - Fetches the Puppet CA certificate from the CA service.
- Registers the node with a noop agent run against the CA.
- Runs the agent a few times against the compile master, then enables the
puppetservice and disables itself.
Puppet CA endpoint
The CA endpoint defaults to the in-cluster puppetserver CA service
puppetca.k8s.syd1.au.unkin.net:8140 (serving the standard
/puppet-ca/v1/certificate/ca API).
It is overridable via the environment. The puppet-initial.service unit reads
/etc/sysconfig/puppet-initial (EnvironmentFile=-, so the file is optional),
which the RPM ships as a commented %config(noreplace) example:
| Variable | Default | Purpose |
|---|---|---|
PUPPETCA_HOST |
puppetca.k8s.syd1.au.unkin.net |
CA hostname (CA cert fetch + --server for registration). |
PUPPETCA_PORT |
8140 |
CA API port. |
Overriding from kickstart
A kickstart %post can point a host at a different CA without rebuilding the
RPM by writing the sysconfig file before the service starts:
%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF