Files
rpmbuilder/rpms/puppet-initial
unkin-agent f1e2b1a2dc
ci/woodpecker/pr/build-fedora43 Pipeline was successful
ci/woodpecker/pr/build-fedora42 Pipeline was successful
ci/woodpecker/pr/build-almalinux8 Pipeline failed
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build-almalinux9 Pipeline was successful
ci/woodpecker/pr/build-fedora44 Pipeline was successful
ci: use container-rpmbuilder image
2026-10-05 14:39:54 +11:00
..

puppet-initial

A firstrun bootstrap script and oneshot systemd service that initialises a freshly-provisioned host into Puppet:

  1. Sets the FQDN under .main.unkin.net.
  2. Fetches the Puppet CA certificate from the CA service.
  3. Registers the node with a noop agent run against the CA.
  4. Runs the agent a few times against the compile master, then enables the puppet service and disables itself.

Puppet CA endpoint

The CA endpoint defaults to the in-cluster puppetserver CA service puppetca.k8s.syd1.au.unkin.net:8140 (serving the standard /puppet-ca/v1/certificate/ca API).

It is overridable via the environment. The puppet-initial.service unit reads /etc/sysconfig/puppet-initial (EnvironmentFile=-, so the file is optional), which the RPM ships as a commented %config(noreplace) example:

Variable Default Purpose
PUPPETCA_HOST puppetca.k8s.syd1.au.unkin.net CA hostname (CA cert fetch + --server for registration).
PUPPETCA_PORT 8140 CA API port.

Overriding from kickstart

A kickstart %post can point a host at a different CA without rebuilding the RPM by writing the sysconfig file before the service starts:

%post
cat > /etc/sysconfig/puppet-initial <<'EOF'
PUPPETCA_HOST=puppetca.k8s.syd1.au.unkin.net
PUPPETCA_PORT=8140
EOF