Dual-write ENC data into encapi alongside Cobbler
Build / build (pull_request) Failing after 11m25s

Seed encapi (statuses, roles, prodnxsr node assignments) and make the
instance module also create an encapi_node for every VM, so the k8s
puppetserver ENC can cut over from Cobbler. Cobbler/puppetca/puppetdb
resources are left untouched.

- Add config/encapi leaf + modules/encapi driving statuses/roles/nodes
  from YAML (3 statuses, 51 roles, 13 prodnxsr physical nodes).
- Add encapi_node to modules/instance (certname, role, environment).
- Wire encapi provider into root.hcl required_providers and the module
  providers; plumb ENCAPI_WRITE_TOKEN via Makefile vault_env.
This commit is contained in:
2026-07-24 22:46:26 +10:00
parent 6edda8ef32
commit 4b9a6de83b
13 changed files with 249 additions and 1 deletions
+29
View File
@@ -0,0 +1,29 @@
resource "encapi_status" "this" {
for_each = var.statuses
name = each.key
description = each.value.description
}
resource "encapi_role" "this" {
for_each = var.roles
name = each.key
description = each.value.description
default_params = each.value.default_params == null ? null : jsonencode(each.value.default_params)
}
resource "encapi_node" "this" {
for_each = var.nodes
certname = each.key
role = each.value.role
environment = each.value.environment
params = each.value.params == null ? null : jsonencode(each.value.params)
# Nodes FK-require their role and status to exist first.
depends_on = [
encapi_role.this,
encapi_status.this,
]
}
+10
View File
@@ -0,0 +1,10 @@
provider "encapi" {
endpoint = var.encapi_endpoint
# token defaults to the ENCAPI_WRITE_TOKEN environment variable
}
variable "encapi_endpoint" {
description = "The encapi server base URL."
type = string
default = "https://encapi.k8s.syd1.au.unkin.net"
}
+37
View File
@@ -0,0 +1,37 @@
variable "statuses" {
description = <<EOT
Map of encapi statuses (Puppet environments) to seed. Keyed by status name.
Each value may carry an optional description.
EOT
type = map(object({
description = optional(string)
}))
default = {}
}
variable "roles" {
description = <<EOT
Map of encapi roles to seed. Keyed by role class name (e.g. roles::base).
Each value may carry an optional description and a default_params object that
is jsonencode()'d into the role's inheritable defaults.
EOT
type = map(object({
description = optional(string)
default_params = optional(any)
}))
default = {}
}
variable "nodes" {
description = <<EOT
Map of encapi node assignments to seed. Keyed by certname. Each value pins the
node to a role and environment (which must exist as a role/status above), with
optional per-node params jsonencode()'d into the ENC output.
EOT
type = map(object({
role = string
environment = string
params = optional(any)
}))
default = {}
}
+8
View File
@@ -0,0 +1,8 @@
terraform {
required_providers {
encapi = {
source = "git.unkin.net/unkin/encapi"
version = "0.1.0"
}
}
}
+11
View File
@@ -97,6 +97,17 @@ resource "puppetdb_node" "this" {
depends_on = [incus_instance.this]
}
# Dual-write the ENC assignment into encapi alongside the Cobbler system above.
# The role and environment must already exist in encapi (seeded by the
# config/encapi leaf); apply that leaf before the instance leaves.
resource "encapi_node" "this" {
certname = "${var.name}.${var.cobbler_domain}"
role = var.cobbler_mgmt_classes[0]
environment = var.encapi_environment
depends_on = [incus_instance.this]
}
resource "null_resource" "wait_for_instance_ready" {
depends_on = [incus_instance.this]
+5
View File
@@ -17,3 +17,8 @@ provider "puppetca" {
cert = var.puppet_cert_pub
key = var.puppet_cert_priv
}
provider "encapi" {
endpoint = var.encapi_endpoint
# token defaults to the ENCAPI_WRITE_TOKEN environment variable
}
+15
View File
@@ -170,3 +170,18 @@ variable "check_on_instance_creation" {
type = bool
default = false
}
variable "encapi_endpoint" {
description = "The encapi server base URL."
type = string
default = "https://encapi.k8s.syd1.au.unkin.net"
}
variable "encapi_environment" {
description = <<EOT
Environment (encapi_status) to pin this instance to in encapi. Defaults to
"production" to match the environment used by puppetca_certificate today.
EOT
type = string
default = "production"
}