Dual-write ENC data into encapi alongside Cobbler
Build / build (pull_request) Failing after 11m25s

Seed encapi (statuses, roles, prodnxsr node assignments) and make the
instance module also create an encapi_node for every VM, so the k8s
puppetserver ENC can cut over from Cobbler. Cobbler/puppetca/puppetdb
resources are left untouched.

- Add config/encapi leaf + modules/encapi driving statuses/roles/nodes
  from YAML (3 statuses, 51 roles, 13 prodnxsr physical nodes).
- Add encapi_node to modules/instance (certname, role, environment).
- Wire encapi provider into root.hcl required_providers and the module
  providers; plumb ENCAPI_WRITE_TOKEN via Makefile vault_env.
This commit is contained in:
2026-07-24 22:46:26 +10:00
parent 6edda8ef32
commit 4b9a6de83b
13 changed files with 249 additions and 1 deletions
+44
View File
@@ -0,0 +1,44 @@
# encapi node assignments for the 13 prodnxsr* physical nodes.
# These hosts are NOT managed by the incus instance module (they are the
# bare-metal hypervisors / k8s nodes), so they are seeded here explicitly.
# certname -> role from the PuppetDB enc_role fact; environment=develop to
# match their current catalog_environment.
prodnxsr0001.main.unkin.net:
role: roles::infra::k8s::control
environment: develop
prodnxsr0002.main.unkin.net:
role: roles::infra::k8s::control
environment: develop
prodnxsr0003.main.unkin.net:
role: roles::infra::k8s::control
environment: develop
prodnxsr0004.main.unkin.net:
role: roles::infra::k8s::compute
environment: develop
prodnxsr0005.main.unkin.net:
role: roles::infra::k8s::compute
environment: develop
prodnxsr0006.main.unkin.net:
role: roles::infra::k8s::compute
environment: develop
prodnxsr0007.main.unkin.net:
role: roles::infra::k8s::compute
environment: develop
prodnxsr0008.main.unkin.net:
role: roles::infra::k8s::compute
environment: develop
prodnxsr0009.main.unkin.net:
role: roles::infra::incus::node
environment: develop
prodnxsr0010.main.unkin.net:
role: roles::infra::incus::node
environment: develop
prodnxsr0011.main.unkin.net:
role: roles::infra::incus::node
environment: develop
prodnxsr0012.main.unkin.net:
role: roles::infra::incus::node
environment: develop
prodnxsr0013.main.unkin.net:
role: roles::infra::incus::node
environment: develop
+55
View File
@@ -0,0 +1,55 @@
# encapi roles: every distinct Puppet role class used across
# config/instances/*/config.yaml (cobbler_mgmt_classes[0]) PLUS the roles
# run by the 13 prodnxsr physical nodes (from PuppetDB enc_role fact).
# Values are empty maps; add description/default_params here when needed.
roles::apps::jupyter::hub: {}
roles::apps::media::jellyfin: {}
roles::apps::media::lidarr: {}
roles::apps::media::nzbget: {}
roles::apps::media::prowlarr: {}
roles::apps::media::radarr: {}
roles::apps::media::readarr: {}
roles::apps::media::sonarr: {}
roles::apps::music::gonic: {}
roles::base: {}
roles::infra::auth::glauth: {}
roles::infra::ceph::rgw: {}
roles::infra::cobbler::server: {}
roles::infra::dhcp::server: {}
roles::infra::dns::externaldns: {}
roles::infra::dns::master: {}
roles::infra::dns::resolver: {}
roles::infra::git::redis: {}
roles::infra::git::runner: {}
roles::infra::git::server: {}
roles::infra::halb::haproxy2: {}
roles::infra::incus::imagehost: {}
roles::infra::incus::node: {}
roles::infra::k8s::compute: {}
roles::infra::k8s::control: {}
roles::infra::logs::vlagent: {}
roles::infra::logs::vlinsert: {}
roles::infra::logs::vlselect: {}
roles::infra::logs::vlstorage: {}
roles::infra::mail::backend: {}
roles::infra::mail::gateway: {}
roles::infra::metrics::grafana: {}
roles::infra::metrics::prometheus: {}
roles::infra::metrics::vmagent: {}
roles::infra::metrics::vminsert: {}
roles::infra::metrics::vmselect: {}
roles::infra::metrics::vmstorage: {}
roles::infra::nomad::agentv2: {}
roles::infra::nomad::server: {}
roles::infra::pki::certbot: {}
roles::infra::proxy::jumphost: {}
roles::infra::puppetboard::server: {}
roles::infra::puppetdb::api: {}
roles::infra::puppetdb::sql: {}
roles::infra::puppet::master: {}
roles::infra::reposync::repo: {}
roles::infra::reposync::syncer: {}
roles::infra::sql::shared: {}
roles::infra::storage::consul: {}
roles::infra::storage::edgecache: {}
roles::infra::storage::vault: {}
+10
View File
@@ -0,0 +1,10 @@
# encapi statuses == Puppet environments (Cobbler "status").
# Seeded from what the estate actually runs (all nodes today report
# catalog_environment=develop) plus production (the environment the incus
# instance module pins via puppetca_certificate) and testing (implicit).
production:
description: Production environment
develop:
description: Development environment (current default across the estate)
testing:
description: Implicit/transient environment
+19
View File
@@ -0,0 +1,19 @@
locals {
statuses = yamldecode(file("${get_terragrunt_dir()}/statuses.yaml"))
roles = yamldecode(file("${get_terragrunt_dir()}/roles.yaml"))
nodes = yamldecode(file("${get_terragrunt_dir()}/nodes.yaml"))
}
include "root" {
path = find_in_parent_folders("root.hcl")
}
terraform {
source = "${get_repo_root()}/modules/encapi"
}
inputs = {
statuses = local.statuses
roles = local.roles
nodes = local.nodes
}
+5 -1
View File
@@ -26,7 +26,7 @@ inputs = {
generate "backend" {
path = "backend.tf"
if_exists = "overwrite_terragrunt"
contents = <<EOF
contents = <<EOF
terraform {
required_providers {
vault = {
@@ -49,6 +49,10 @@ terraform {
source = "camptocamp/puppetdb"
version = "2.0.0"
}
encapi = {
source = "git.unkin.net/unkin/encapi"
version = "0.1.0"
}
}
backend "consul" {
address = "${local.consul_addr}"