Puppet Class: profile::puppetmaster::backend

Defined in:
modules/profile/manifests/puppetmaster/backend.pp

Overview

Parameters:

  • config (Any) (defaults to: hiera('profile::puppetmaster::backend::config', {}))
  • secure_private (Any) (defaults to: hiera('profile::puppetmaster::backend::config', true))
  • prevent_cherrypicks (Any) (defaults to: hiera('profile::puppetmaster::backend::prevent_cherrypicks', true))
  • ca_server (Stdlib::Host) (defaults to: lookup('puppet_ca_server'))
  • puppetmasters (Any) (defaults to: hiera('puppetmaster::servers'))
  • allow_from (Any) (defaults to: [ '*.wikimedia.org', '*.eqiad.wmnet', '*.ulsfo.wmnet', '*.esams.wmnet', '*.codfw.wmnet', '*.eqsin.wmnet'])
  • extra_auth_rules (Any) (defaults to: '')


3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
# File 'modules/profile/manifests/puppetmaster/backend.pp', line 3

class profile::puppetmaster::backend(
    $config = hiera('profile::puppetmaster::backend::config', {}),
    # should $secure_priviate really get its config from the same
    # place as $config?
    $secure_private = hiera('profile::puppetmaster::backend::config', true),
    $prevent_cherrypicks = hiera('profile::puppetmaster::backend::prevent_cherrypicks', true),
    Stdlib::Host $ca_server = lookup('puppet_ca_server'),
    $puppetmasters = hiera('puppetmaster::servers'),
    $allow_from = [
      '*.wikimedia.org',
      '*.eqiad.wmnet',
      '*.ulsfo.wmnet',
      '*.esams.wmnet',
      '*.codfw.wmnet',
      '*.eqsin.wmnet'],
    $extra_auth_rules = '',
) {

    $common_config = {
        'ca'              => false,
        'ca_server'       => $ca_server,
        'stringify_facts' => false,
    }
    $base_config = merge($config, $common_config)

    class { '::profile::puppetmaster::common':
        base_config => $base_config,
    }

    class { '::httpd':
        modules => ['passenger'],
    }

    require_package('libapache2-mod-passenger')

    class { '::puppetmaster':
        server_type         => 'backend',
        config              => $::profile::puppetmaster::common::config,
        secure_private      => $secure_private,
        prevent_cherrypicks => $prevent_cherrypicks,
        allow_from          => $allow_from,
        extra_auth_rules    => $extra_auth_rules,
        ca_server           => $ca_server,
    }

    $puppetmaster_frontend_ferm = join(keys($puppetmasters), ' ')
    ferm::service { 'ssh_puppet_merge':
        proto  => 'tcp',
        port   => '22',
        srange => "(@resolve((${puppetmaster_frontend_ferm})) @resolve((${puppetmaster_frontend_ferm}), AAAA))"
    }
    ferm::service { 'puppetmaster-backend':
        proto  => 'tcp',
        port   => 8141,
        srange => "(@resolve((${puppetmaster_frontend_ferm})) @resolve((${puppetmaster_frontend_ferm}), AAAA))"
    }
    require ::profile::conftool::client
}