diff --git a/Vagrantfile b/Vagrantfile new file mode 100644 index 0000000..dad2141 --- /dev/null +++ b/Vagrantfile @@ -0,0 +1,75 @@ +# -*- mode: ruby -*- +# vi: set ft=ruby : + +Vagrant.configure('2') do |config| + # define box to use + config.vm.box = 'sbeliakou/centos-7.2-x86_64' + + # define puppet master server + config.vm.define 'master' do |master| + master.vm.hostname = 'master.lab' + master.vm.network 'private_network', ip: '192.0.0.100' + master.vm.provider 'virtualbox' do |v| + v.name = 'master' + v.memory = 4096 + v.cpus = 2 + v.linked_clone = true + end + master.vm.provision 'shell', inline: <<-SHELL + nmcli connection reload + systemctl restart network.service + grep client /etc/hosts + [ $? -ne 0 ] && echo "192.0.0.105 client.lab" >> /etc/hosts + /bin/cp /vagrant/hosts /etc/ + yum install -y https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm + yum install -y http://yum.postgresql.org/9.4/redhat/rhel-7-x86_64/pgdg-redhat94-9.4-2.noarch.rpm + yum install -y puppetserver + systemctl enable puppetserver + /bin/cp /vagrant/site.pp /etc/puppetlabs/code/environments/production/manifests + /bin/cp /vagrant/autosign.conf /etc/puppetlabs/puppet/ + /bin/cp /vagrant/server_puppet.conf /etc/puppetlabs/puppet/puppet.conf + mkdir -p /etc/puppetlabs/code/environments/prod/{manifests,modules} + /bin/cp /vagrant/prod_site.pp /etc/puppetlabs/code/environments/prod/manifests/site.pp + systemctl restart puppetserver + source ~/.bashrc + yum install postgresql94-server postgresql94-contrib -y + /usr/pgsql-9.4/bin/postgresql94-setup initdb + yes | cp /vagrant/pg_hba.conf /var/lib/pgsql/9.4/data/ + systemctl enable postgresql-9.4.service + systemctl start postgresql-9.4.service + cd / + sudo -u postgres psql -c "create user puppetdb password 'puppetdb'" + sudo -u postgres psql -c "create database puppetdb owner puppetdb" + puppet module install puppetlabs-puppetdb --version 5.1.2 + puppet module install puppetlabs-mysql --version 3.10.0 --environment prod + puppet module install puppetlabs-apache --version 1.11.0 + puppet module install spotify-puppetexplorer --version 1.1.1 + puppet module install puppet-nginx --version 0.6.0 --environment prod + puppet agent -t + systemctl stop iptables + SHELL + end + + # define puppet client vm + config.vm.define 'client' do |client| + client.vm.hostname = 'client.lab' + client.vm.network 'private_network', ip: '192.0.0.105' + client.vm.provider 'virtualbox' do |v| + v.name = 'client' + v.memory = 1024 + v.cpus = 1 + v.linked_clone = true + end + client.vm.provision 'shell', inline: <<-SHELL + nmcli connection reload + systemctl restart network.service + grep master /etc/hosts + [ $? -ne 0 ] && echo "192.0.0.100 master.lab" >> /etc/hosts + yum install -y https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm + yum install -y puppet-agent + /bin/cp /vagrant/client_puppet.conf /etc/puppetlabs/puppet/puppet.conf + source ~/.bashrc + puppet agent -t + SHELL + end +end diff --git a/autosign.conf b/autosign.conf new file mode 100644 index 0000000..fe48d3f --- /dev/null +++ b/autosign.conf @@ -0,0 +1 @@ +client.lab diff --git a/client_info.png b/client_info.png new file mode 100644 index 0000000..8a412c4 Binary files /dev/null and b/client_info.png differ diff --git a/client_puppet.conf b/client_puppet.conf new file mode 100644 index 0000000..af1ba67 --- /dev/null +++ b/client_puppet.conf @@ -0,0 +1,5 @@ +[main] +certname = client.lab +server = master.lab +environment = prod +runinterval = 3m diff --git a/hosts b/hosts new file mode 100644 index 0000000..0b22394 --- /dev/null +++ b/hosts @@ -0,0 +1,4 @@ +127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 +::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 +192.0.0.100 master.lab +192.0.0.105 client.lab diff --git a/lesson13_mysql_client.png b/lesson13_mysql_client.png new file mode 100644 index 0000000..4b4d8f1 Binary files /dev/null and b/lesson13_mysql_client.png differ diff --git a/lesson13_nginx.png b/lesson13_nginx.png new file mode 100644 index 0000000..3e3ee88 Binary files /dev/null and b/lesson13_nginx.png differ diff --git a/pg_hba.conf b/pg_hba.conf new file mode 100644 index 0000000..2ab4f05 --- /dev/null +++ b/pg_hba.conf @@ -0,0 +1,3 @@ +local all all peer +host all all 127.0.0.1/32 md5 +host all all ::1/128 md5 diff --git a/prod_site.pp b/prod_site.pp new file mode 100644 index 0000000..9168e6d --- /dev/null +++ b/prod_site.pp @@ -0,0 +1,48 @@ +# node definitions.) + +## Active Configurations ## + +# Disable filebucket by default for all File resources: +File { backup => false } + +# DEFAULT NODE +# Node definitions in this file are merged with node data from the console. See +# http://docs.puppetlabs.com/guides/language_guide.html#nodes for more on +# node definitions. + +# The default node definition matches any node lacking a more specific node +# definition. If there are no other nodes in this file, classes declared here +# will be included in every node's catalog, *in addition* to any classes +# specified in the console for that node. + +node default { + # This is where you can declare classes for all nodes. + # Example: + # class { 'my_class': } + notify { "Node ${::fqdn} is up and running!": } +} + +node 'client.lab' { + class { 'nginx': } + class { '::mysql::server': + root_password => 'password', + } + + mysql_database { 'prod_mdb': + ensure => present, + charset => 'utf8', + } + + mysql_user { 'prod_user@localhost': + ensure => present, + password_hash => mysql_password('prod_password'), + } + + mysql_grant { 'prod_user@localhost/prod_mdb.*': + ensure => present, + options => ['GRANT'], + privileges => ['ALL'], + table => 'prod_mdb.*', + user => 'prod_user@localhost', + } +} \ No newline at end of file diff --git a/server_puppet.conf b/server_puppet.conf new file mode 100644 index 0000000..3288248 --- /dev/null +++ b/server_puppet.conf @@ -0,0 +1,19 @@ +# This file can be used to override the default puppet settings. +# See the following links for more details on what settings are available: +# - https://docs.puppetlabs.com/puppet/latest/reference/config_important_settings.html +# - https://docs.puppetlabs.com/puppet/latest/reference/config_about_settings.html +# - https://docs.puppetlabs.com/puppet/latest/reference/config_file_main.html +# - https://docs.puppetlabs.com/puppet/latest/reference/configuration.html +[main] +certname = master.lab +server = master.lab +environment = production +runinterval = 1h +strict_variables = true + +[master] +vardir = /opt/puppetlabs/server/data/puppetserver +logdir = /var/log/puppetlabs/puppetserver +rundir = /var/run/puppetlabs/puppetserver +pidfile = /var/run/puppetlabs/puppetserver/puppetserver.pid +codedir = /etc/puppetlabs/code diff --git a/site.pp b/site.pp new file mode 100644 index 0000000..5c9dbab --- /dev/null +++ b/site.pp @@ -0,0 +1,39 @@ +# node definitions.) + +## Active Configurations ## + +# Disable filebucket by default for all File resources: +File { backup => false } + +# DEFAULT NODE +# Node definitions in this file are merged with node data from the console. See +# http://docs.puppetlabs.com/guides/language_guide.html#nodes for more on +# node definitions. + +# The default node definition matches any node lacking a more specific node +# definition. If there are no other nodes in this file, classes declared here +# will be included in every node's catalog, *in addition* to any classes +# specified in the console for that node. + +node default { + # This is where you can declare classes for all nodes. + # Example: + # class { 'my_class': } + notify { "Node ${::fqdn} is up and running!": } +} + +node 'master.lab' { + # # Configure puppetdb + class { 'puppetdb::server': + database_host => '127.0.0.1', + confdir => '/etc/puppetlabs/puppetdb/conf.d', + } + # Configure the Puppet master to use puppetdb + class { 'puppetdb::master::config': } + class { 'puppetexplorer': + vhost_options => { + rewrites => [ { rewrite_rule => [ + '^/api/metrics/v1/mbeans/puppetlabs.puppetdb.query.population:type=default,name=(.*)$ https://%{HTTP_HOST}/api/metrics/v1/mbeans/puppetlabs.puppetdb.population:name=$1 [R=301,L]' + ] } ] } + } +} \ No newline at end of file