585d32b15c
Automate the PuppetDB reality import (issue #1) by querying pdbmux — the PuppetDB multiplexer whose HTTPS gateway is reachable from CI/workstations, unlike raw PuppetDB — instead of PuppetDB directly, and shaping the result to the NetBox reality side the devices module reconciles. - Add tools/backfill (Go): query pdbmux /pdb/query/v4/facts for the 13 existing physicals and emit per-host reality YAML — serial/model/UUID, every recordable interface (real NICs plus overlay/loopback/kube-lb) with MAC and CIDR IPs, and CPU/RAM/disk inventory. Filter ephemeral Calico veths and Ceph RBD volumes; take interface names from Facter, never assume them. - Emit deterministic, idempotent, yamllint-clean output into config/au/syd1/reality/<host>.yaml, generated for prodnxsr0001-0013. - Extend modules/infra with a reality variable and reality.tf creating netbox_device_interface/netbox_mac_address/netbox_ip_address/ netbox_inventory_item and device serial; wire reality only for hosts that also have an intent device. - Load reality/*.yaml in the terragrunt env; add `make backfill`; add a go vet/test woodpecker job; drop the in-cluster-only Python script. Closes #1 Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
52 lines
2.0 KiB
Makefile
52 lines
2.0 KiB
Makefile
.PHONY: init plan apply format pre-commit backfill
|
|
|
|
# Hosts whose hardware reality is backfilled from pdbmux into NetBox. Override to
|
|
# add/limit hosts, e.g. `make backfill BACKFILL_HOSTS="prodnxsr0001 prodnxsr0002"`.
|
|
BACKFILL_HOSTS ?= prodnxsr0001 prodnxsr0002 prodnxsr0003 prodnxsr0004 prodnxsr0005 \
|
|
prodnxsr0006 prodnxsr0007 prodnxsr0008 prodnxsr0009 prodnxsr0010 prodnxsr0011 \
|
|
prodnxsr0012 prodnxsr0013
|
|
PDBMUX_URL ?= https://pdbmux.k8s.syd1.au.unkin.net/pdb/query/v4/facts
|
|
BACKFILL_OUT ?= config/au/syd1/reality
|
|
|
|
VAULT_AUTH_METHOD ?= approle
|
|
VAULT_K8S_ROLE ?= woodpecker_terraform_infra
|
|
VAULT_K8S_MOUNT ?= auth/k8s/au/syd1
|
|
VAULT_K8S_JWT_PATH ?= /var/run/secrets/kubernetes.io/serviceaccount/token
|
|
|
|
define vault_env
|
|
@export VAULT_ADDR="https://vault.service.consul:8200" && \
|
|
if [ "$(VAULT_AUTH_METHOD)" = "kubernetes" ]; then \
|
|
export VAULT_TOKEN=$$(vault write -field=token $(VAULT_K8S_MOUNT)/login role=$(VAULT_K8S_ROLE) jwt=$$(cat $(VAULT_K8S_JWT_PATH))); \
|
|
else \
|
|
export VAULT_TOKEN=$$(vault write -field=token auth/approle/login role_id=$$VAULT_ROLEID); \
|
|
fi && \
|
|
export CONSUL_HTTP_TOKEN=$$(vault read -field=token consul_root/au/syd1/creds/terraform-infra)
|
|
endef
|
|
|
|
init:
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --non-interactive init -- -upgrade
|
|
|
|
plan: init
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --parallelism 4 --non-interactive plan
|
|
|
|
apply: init
|
|
@$(call vault_env) && \
|
|
terragrunt run --all --parallelism 2 --non-interactive apply
|
|
|
|
format:
|
|
@echo "Formatting OpenTofu files..."
|
|
@tofu fmt -recursive .
|
|
@echo "Formatting Terragrunt files..."
|
|
@terragrunt hcl fmt
|
|
|
|
pre-commit:
|
|
@uvx pre-commit run --all-files
|
|
|
|
# Regenerate NetBox reality YAML from pdbmux. Idempotent with stable ordering,
|
|
# so re-running against unchanged facts leaves a clean git diff. Needs network
|
|
# reachability to pdbmux (its HTTPS gateway is reachable from CI/workstations).
|
|
backfill:
|
|
@go -C tools/backfill run . --url "$(PDBMUX_URL)" --out "$(CURDIR)/$(BACKFILL_OUT)" $(BACKFILL_HOSTS)
|