Posts

Showing posts with the label cert

Featured Post

Directory environments in Puppet

Environments are individual groups of Puppet agents each environment have there own completely different manifests and module-paths. This basically is useful for testing changes to our Puppet code before implementing them on production machines. There are two types of implementation of environments structure in Puppet one if directory based and another is config file based here we will see bit of an insight about directory based. As usual for more information about this you can visit puppetlabs official website. On the master node: Append following details in puppet.conf which is placed under /etc/puppet or /etc/puppetlabs/puppet:     Under [main] section add a variable called confdir with value as /etc/puppet or /etc/puppetlabs/puppet     confdir=/etc/puppet Then add information regarding environments/manifests and modulepath in it.      #environments     environmentpath = $confdir/environments  ...

Puppet agent run

Image
Puppet agent ==> Sends node's information and its facts to the master node and requests for Catalog [Complied manifests]. Puppet master checks who is this ? if this machine is authorized[Have a signed certificate or not?] to communicate with it and what all stuff do this machine needs. If incase this is the authorized one. Puppet master will gather all the related manifests and compile them to a catalog and then will send that catalog to the agent node. Puppet agent then will download & apply that catalog to get to the desired state and will create a [success/failure] report for the puppet master. Related docs: Puppet master   Puppet agent

Puppet installation on agent/server

Puppet can be used as a standalone model or as agent/server model. There are basically 2 types of puppet version available in market. Free version of puppet. Enterprise version of puppet which is also know as puppet-enterprise. Here we will be installing the free version of puppet. 0. Enable EPEL repo, you can find the latest version of EPEL on below URL: https://fedoraproject.org/wiki/EPEL 1. Install prerequisites before installing puppet [root@rhel6 ~]# yum install ruby-shadow ruby ruby-libs 2. Resolve the dependencies like ruby(selinux). 3. Install puppetmaster and facter on the server node. [root@rhel6 ~]# yum install puppet-server facter 4. Install puppet and facter on the agent node. [root@rhel6 ~]# yum install puppet facter Once these packages are installed on both the machines. Make sure that your agent node can ping the server node with the name as puppet. [root@rhel6 ~]# ping puppet PING puppet (192.168.122.14) 56(84) bytes of data. 64 bytes fr...

Un-revoke the revoked certificate in Puppet

If you revoked or deleted the puppet agent’s certificate accidentally. Basically it is nearly impossible un-revoke a certificate. The solution is to recover all revoked certificates then revoke other certificates which don’t need to be recovered. But if in-case you have thousands of revoked certificates then its a bit lengthy process. Second one is to generate a new certificate for the client/agent and get that signed by the puppet master.  List of all the certificates which are signed at the moment:  [root@puppet requests]# puppet cert list --all + "fedora20"            (AE:57:40:F6:FC:E1:CD:DD:ED:EE:1E:8C:A7:81:0D:76) + "kubuntu14.sunny.com" (20:6B:A1:E2:A3:DE:B1:95:C8:80:4C:B4:27:2B:C0:A2) + "puppet.sunny.com"    (68:12:76:3C:D0:F8:0D:2D:8B:2B:40:E7:49:2D:55:5B) (alt names: "DNS:puppet", "DNS:puppet.sunny.com") + "rhel6.sunny.com"     (DC:6E:B1:FC:27:1D:7A:2A:85:E7:3E:3A:2...

puppet cert???

*Cert sub-command in Puppet "puppet cert"* It is a utility that manage certificates and requests related to it. The main purpose of this utility are: 1. Generating certificates. 2. Signing certificate requests from puppet clients/agents. As not a single client/agent can communicate with the puppet master with out a signed certificate this is the most important thing. If in-case you want the revoke the certificate for the node you can use the option as clean this will remove all the information related to that particular host from the puppet cert's storage. Make sure you are revoking the correct certificate because it is nearly impossible to un-revoke the certificate but there is a other other way around[will discuss this is later part]. [root@puppet ~]# puppet cert clean rhel6.sunny.com notice: Revoked certificate with serial 4 notice: Removing file Puppet::SSL::Certificate rhel6.sunny.com at '/var/lib/puppet/ssl/ca/signed/rhel6.sunny.com.pem' notice:...

puppet describe???

*Describe sub-command in Puppet "puppet describe" * The puppet describe sub-command can list info about the currently installed resource types on a given machine. This is a built in documentation and a great source of information. It helps us to know the behavior of types, their properties and parameters. "puppet describe -l" — List all of the resource types available on the system. "puppet describe -s <TYPE>" Print short information about a type, without describing every attribute "puppet describe <TYPE>" Shows each and every information about the type which you are referring too. [root@puppet ~]# puppet describe -l These are the types known to puppet: augeas          -  Apply a change or an array of changes to the ... computer        - Computer object management using DirectorySer ... cron            -  Installs a...

puppet apply???

*Apply sub-command in Puppet "puppet apply"* This is the standalone puppet execution tool which is used to apply individual manifests. It is an application that complies and manages configuration on node. Point to note is puppet apply never runs as a daemon like puppet agent. It always runs like a single process which complies a catalog then applies it send a report that's it. Most important option with puppet apply command is modulepath. Suppose you are firing puppet apply XYZ.pp file then it will take the module location as /etc/puppet/modules by default but if in case your modules are there in some other directory suppose /root/puppet-modules then you can use "modulepath" with this location to ask puppet to use it. Running a puppet apply command to apply the changes to the machine with site.pp manifest. [root@puppet manifests]# puppet apply site.pp notice: /Stage[main]/Sudo/File[/etc/sudoers]/content: content changed '{md5}e81452ad78198a...

puppet resource???

*Resources in Puppet "puppet resource"* Understanding Resources is fundamental to understanding how Puppet works. Resources are like building blocks. They can be combined to model the expected state of the systems you manage.  For more information about the resources in puppet you can fire "puppet resource -h" on CLI. This command transforms the current system state into puppet code also it has the ability to modify the current state of the system. Syntax: resource_type { 'resource_name'   attribute => value   ... } Below are the few examples: To see all the users in the machine. [root@puppet ~]# puppet resource user  To see a particular user in the machine.   [root@puppet ~]# puppet resource user sunny user { 'sunny':   ensure           => 'present',   comment          => 'Sunny_B',   gid     ...

Introduction to Puppet

Puppet is an open source configuration management utility. It runs on mostly all Unix/Linux flavors as well as on Microsoft Windows, and includes its own declarative language to describe system configuration. With Puppet, repetitive tasks are automated away, so sysadmins can quickly deploy business applications, scaling easily from tens of servers to thousands, both on-premise and in the cloud. Puppet is written in a declarative language, means you tell Puppet what results you want, rather than how to get there. Puppet is produced by Puppet Labs, founded by Luke Kanies in 2005. It is written in Ruby and released as free software under the GPL. Most of Puppet’s functionality comes from a single puppet command, which has many sub-commands. Most importantly there is a sub-command called resource. The resource subcommand can inspect and modify resources interactively. [root@server manifests]# puppet resource service service { 'NetworkManager':   ensure => 'r...