aboutsummaryrefslogtreecommitdiff
path: root/share/hydra/compile
blob: 6d84c531fddc605a9d791a92c38fb7e14d2004f8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
#!/bin/bash
#
# Compile configuration.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public
# License along with this program.  If not, see
# <http://www.gnu.org/licenses/>.

# Load
source $APP_BASE/lib/hydra/functions || exit 1
hydra_config_load

# Config
CONFIG="$HYDRA_FOLDER/puppet/config/compiled.yaml"
NODES="`hydra $HYDRA nodes`"
FACTS="$HYDRA_FOLDER/puppet/config/facts"
KEYS="$HYDRA_FOLDER/keyring/keys/nodes"

echo "Starting a fresh compiled config..."
mkdir -p "`dirname $CONFIG`"
echo "---"                                                           > $CONFIG
echo "#"                                                            >> $CONFIG
echo "# Compiled configuration."                                    >> $CONFIG
echo "# Do not edit this file. Use 'hydra $HYDRA compile' instead." >> $CONFIG
echo "#"                                                            >> $CONFIG

# Per-node configuration
for node in $NODES; do
  # SSH public keys
  if [ -e "$KEYS/$node/ssh/id_rsa.pub.asc" ]; then
    echo "Adding SSH public key for $node..."
    key="ssh_authorized_key::$node"
    value="$(keyringer $HYDRA decrypt nodes/$node/ssh/id_rsa.pub 2> /dev/null | cut -d ' ' -f 2)"
    echo "$key: '$value'" >> $CONFIG
  fi
done

echo "Compiling data from collected facts..."

# SSH known_hosts
echo "sshkeys:" >> $CONFIG

for node in $NODES; do
  if [ -e "$FACTS/${node}.yaml" ]; then
    rsakey="$(grep sshrsakey: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"
    sshed25519key="$(grep sshed25519key: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"
    sshecdsakey="$(grep sshecdsakey: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"

    host_aliases=""
    ssh_ports="`hydra_hiera_query $node sshd::ports`"

    if [ "$ssh_ports" != "nil" ] && [ ! -z "$ssh_ports" ]; then
      ssh_ports="`echo $ssh_ports | sed -e 's/\[//g' -e 's/\]//g' -e 's/,//g'`"

      for port in $ssh_ports; do
        if [ -z "$host_aliases" ]; then
          host_aliases="'[${node}]:$port'"
        else
          host_aliases="$host_aliases, '[${node}]:$port'"
        fi
      done
    fi

    if [ ! -z "$rsakey" ]; then
      #echo "  $node-rsa:"                 >> $CONFIG
      echo "  $node:"                      >> $CONFIG
      #echo "   name         : '$node'"    >> $CONFIG
      echo "    ensure       : 'present'"  >> $CONFIG
      echo "    type         : 'ssh-rsa'"  >> $CONFIG
      echo "    key          : '$rsakey'"  >> $CONFIG

      if [ ! -z "$host_aliases" ]; then
        echo "    host_aliases : [ $host_aliases ]" >> $CONFIG
      fi
    fi

    # See [PUP-6589] Resource Type sshkey doesn't allow the declaration of multiple SSH host keys for one host
    # https://tickets.puppetlabs.com/browse/PUP-6589
    #if [ ! -z "$sshed25519key" ]; then
    #  echo "  $node-sshed25519key:"            >> $CONFIG
    #  echo "    name  : '$node'"               >> $CONFIG
    #  echo "    ensure: 'present'"             >> $CONFIG
    #  echo "    type  : 'ssh-ed25519'"         >> $CONFIG
    #  echo "    key   : '$sshed25519key'"      >> $CONFIG
    #fi

    #if [ ! -z "$sshecdsakey" ]; then
    #  echo "  $node-sshecdsakey:"              >> $CONFIG
    #  echo "    name  : '$node'"               >> $CONFIG
    #  echo "    ensure: 'present'"             >> $CONFIG
    #  echo "    type  : 'ecdsa-sha2-nistp256'" >> $CONFIG
    #  echo "    key   : '$sshecdsakey'"        >> $CONFIG
    #fi
  fi
done