Puppet Class: profile::kubernetes::mediawiki_runner

Defined in:
modules/profile/manifests/kubernetes/mediawiki_runner.pp

Summary

Class to add specific data to a k8s node running mediawiki

Overview

SPDX-License-Identifier: Apache-2.0

Parameters:

  • kubelet_node_labels (Optional[Array[String]]) (defaults to: lookup('profile::kubernetes::node::kubelet_node_labels', { default_value => [] }))


3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
# File 'modules/profile/manifests/kubernetes/mediawiki_runner.pp', line 3

class profile::kubernetes::mediawiki_runner(
    Optional[Array[String]] $kubelet_node_labels = lookup('profile::kubernetes::node::kubelet_node_labels', { default_value => [] })
) {
    # For now, assume we can use any node that's not marked as dedicated.
    $reserved_node = /dedicated=.*/ in $kubelet_node_labels
    $ensure  = $reserved_node.bool2str('absent', 'present')

    $command = '/usr/local/sbin/mediawiki-image-download'
    file { $command:
        ensure => $ensure,
        mode   => '0544',
        owner  => 'root',
        group  => 'root',
        source => 'puppet:///modules/profile/kubernetes/node/mediawiki-image-download.sh'
    }
    ## Scap "client"
    # Please note: if we ever want to actually use the scap client to not just deliver commands but to
    # distribute the code, we should include profile::mediawiki::scap_client instead
    # The following is copied over from mediawiki::users; TODO: refactor and DRY
    group { 'mwdeploy':
        ensure => $ensure,
        system => true,
    }

    user { 'mwdeploy':
        ensure     => $ensure,
        shell      => '/bin/bash',
        home       => '/var/lib/mwdeploy',
        system     => true,
        managehome => true,
    }

    ssh::userkey { 'mwdeploy':
        ensure  => $ensure,
        content => secret('keyholder/mwdeploy.pub'),
    }
    # Grant mwdeploy sudo rights to download the mediawiki image.
    sudo::user { 'mwdeploy':
        ensure     => $ensure,
        privileges => [
            "ALL = (root) NOPASSWD: ${command} *",
        ]
    }

    class { 'scap::ferm':
        ensure => $ensure,
    }

    unless $reserved_node {
        ## GeoIP data
        # Make sure that the GeoIP data is copied locally on the node before starting the kubelet
        # service so it can be available to the mediawiki pods. T288375
        class { 'geoip::data::puppet':
            fetch_ipinfo_dbs => true,
            before           => Service['kubelet'],
        }
    }

}