Dual-write ENC data into encapi alongside Cobbler
Build / build (pull_request) Failing after 11m25s

Seed encapi (statuses, roles, prodnxsr node assignments) and make the
instance module also create an encapi_node for every VM, so the k8s
puppetserver ENC can cut over from Cobbler. Cobbler/puppetca/puppetdb
resources are left untouched.

- Add config/encapi leaf + modules/encapi driving statuses/roles/nodes
  from YAML (3 statuses, 51 roles, 13 prodnxsr physical nodes).
- Add encapi_node to modules/instance (certname, role, environment).
- Wire encapi provider into root.hcl required_providers and the module
  providers; plumb ENCAPI_WRITE_TOKEN via Makefile vault_env.
This commit is contained in:
2026-07-24 22:46:26 +10:00
parent 6edda8ef32
commit 4b9a6de83b
13 changed files with 249 additions and 1 deletions
+15
View File
@@ -170,3 +170,18 @@ variable "check_on_instance_creation" {
type = bool
default = false
}
variable "encapi_endpoint" {
description = "The encapi server base URL."
type = string
default = "https://encapi.k8s.syd1.au.unkin.net"
}
variable "encapi_environment" {
description = <<EOT
Environment (encapi_status) to pin this instance to in encapi. Defaults to
"production" to match the environment used by puppetca_certificate today.
EOT
type = string
default = "production"
}