c6df3a7619
ci/woodpecker/push/deploy-fedora42 Pipeline was successful
ci/woodpecker/push/deploy-fedora44 Pipeline was successful
ci/woodpecker/push/deploy-fedora43 Pipeline was successful
ci/woodpecker/push/deploy-almalinux9 Pipeline was successful
ci/woodpecker/push/deploy-almalinux8 Pipeline was successful
## Why The `puppet-initial` firstrun bootstrap RPM hardcoded the legacy Consul-discovered CA endpoint `puppetca.query.consul:8140`. That VM-era CA is being replaced by the in-cluster puppetserver CA service `puppetca.k8s.syd1.au.unkin.net`. Rather than swap one hardcoded host for another, the endpoint is now configurable so kickstart can override it per host. Verified the new service serves the same Puppet CA API on the same port: `https://puppetca.k8s.syd1.au.unkin.net:8140/puppet-ca/v1/certificate/ca` returns HTTP 200 with a valid Puppet CA cert. ## Changes - Default the CA host to `puppetca.k8s.syd1.au.unkin.net` (still port `8140`, same `/puppet-ca/v1/certificate/ca` path). - Bootstrap script reads `PUPPETCA_HOST` / `PUPPETCA_PORT` from the environment, falling back to the defaults, and uses them for both the CA cert fetch and the `--server` of the initial noop registration run. - Add `EnvironmentFile=-/etc/sysconfig/puppet-initial` to the systemd unit so kickstart `%post` can drop overrides in there. - Ship a commented example config at `/etc/sysconfig/puppet-initial` as `%config(noreplace)`. - Add a package README documenting the override, with a kickstart `%post` example. - Bump el8/el9 build version `1.0.3` -> `1.0.4` so a new RPM is published (dedup skips identical filenames). Note: the run loop still targets `puppet.query.consul` (the compile master, a separate host from the CA) — intentionally left unchanged; scope here is the CA endpoint only. ## Validation - `make test` — 72 passed - pre-commit (metadata jsonschema, yamllint, shebang/executable checks) — all pass - Local `nfpm pkg` build: RPM assembles; `/etc/sysconfig/puppet-initial` correctly listed by `rpm -qcp` as a config file; packaged script carries the new default + env wiring. https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv --------- Co-authored-by: Ben Vincent <neotheo@gmail.com> Reviewed-on: #171 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
1.6 KiB
1.6 KiB
puppet-initial
A firstrun bootstrap script and oneshot systemd service that initialises a freshly-provisioned host into Puppet:
- Sets the FQDN under
.main.unkin.net. - Fetches the Puppet CA certificate from the CA service.
- Registers the node with a noop agent run against the CA.
- Runs the agent a few times against the compile master, then enables the
puppetservice and disables itself.
Puppet CA endpoint
The CA endpoint defaults to the in-cluster puppetserver CA service
puppetca.k8s.syd1.au.unkin.net:8140 (serving the standard
/puppet-ca/v1/certificate/ca API).
It is overridable via the environment. The puppet-initial.service unit reads
/etc/sysconfig/puppet-initial (EnvironmentFile=-, so the file is optional),
which the RPM ships as a commented %config(noreplace) example:
| Variable | Default | Purpose |
|---|---|---|
PUPPETCA_HOST |
puppetca.k8s.syd1.au.unkin.net |
CA hostname (CA cert fetch + --server for registration). |
PUPPETCA_PORT |
8140 |
CA API port. |
Overriding from kickstart
A kickstart %post can point a host at a different CA without rebuilding the
RPM by writing the sysconfig file before the service starts:
%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF