Puppet Class: profile::puppetmaster::backend

Defined in:
modules/profile/manifests/puppetmaster/backend.pp

Overview

Parameters:

  • config (Hash) (defaults to: lookup('profile::puppetmaster::backend::config', {'default_value' => {}}))
  • secure_private (Any) (defaults to: lookup('profile::puppetmaster::backend::config', {'default_value' => true}))
  • prevent_cherrypicks (Boolean) (defaults to: lookup('profile::puppetmaster::backend::prevent_cherrypicks', {'default_value' => true }))
  • ca_server (Stdlib::Host) (defaults to: lookup('puppet_ca_server'))
  • servers (Hash[String, Puppetmaster::Backends]) (defaults to: lookup(puppetmaster::servers))
  • allow_from (Array[String]) (defaults to: [ '*.wikimedia.org', '*.eqiad.wmnet', '*.ulsfo.wmnet', '*.esams.wmnet', '*.codfw.wmnet', '*.eqsin.wmnet', '*.drmrs.wmnet'])
  • extra_auth_rules (String) (defaults to: '')


3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
# File 'modules/profile/manifests/puppetmaster/backend.pp', line 3

class profile::puppetmaster::backend(
    Hash $config = lookup('profile::puppetmaster::backend::config', {'default_value' => {}}),
    # should $secure_priviate really get its config from the same
    # place as $config?
    $secure_private = lookup('profile::puppetmaster::backend::config', {'default_value' => true}),
    Boolean $prevent_cherrypicks = lookup('profile::puppetmaster::backend::prevent_cherrypicks', {'default_value' =>  true }),
    Stdlib::Host $ca_server = lookup('puppet_ca_server'),
    Hash[String, Puppetmaster::Backends] $servers = lookup(puppetmaster::servers),
    Array[String] $allow_from = [
      '*.wikimedia.org',
      '*.eqiad.wmnet',
      '*.ulsfo.wmnet',
      '*.esams.wmnet',
      '*.codfw.wmnet',
      '*.eqsin.wmnet',
      '*.drmrs.wmnet'],
    String $extra_auth_rules = '',

) {

    ensure_packages(['libapache2-mod-passenger'])

    $common_config = {
        'ca'              => false,
        'ca_server'       => $ca_server,
        'stringify_facts' => false,
    }
    $base_config = merge($config, $common_config)

    class { 'profile::puppetmaster::common':
        base_config => $base_config,
    }

    class { 'httpd':
        remove_default_ports => true,
        modules              => ['passenger'],
    }

    class { 'puppetmaster':
        server_type         => 'backend',
        config              => $::profile::puppetmaster::common::config,
        secure_private      => $secure_private,
        prevent_cherrypicks => $prevent_cherrypicks,
        allow_from          => $allow_from,
        extra_auth_rules    => $extra_auth_rules,
        ca_server           => $ca_server,
        servers             => $servers,
    }

    $puppetmaster_frontend_ferm = join(keys($servers), ' ')
    ferm::service { 'ssh_puppet_merge':
        proto  => 'tcp',
        port   => '22',
        srange => "(@resolve((${puppetmaster_frontend_ferm})) @resolve((${puppetmaster_frontend_ferm}), AAAA))"
    }
    ferm::service { 'puppetmaster-backend':
        proto  => 'tcp',
        port   => 8141,
        srange => "(@resolve((${puppetmaster_frontend_ferm})) @resolve((${puppetmaster_frontend_ferm}), AAAA))"
    }
    require profile::conftool::client
}