3 # @param pool_name A string to be used in pool names
4 # @param db_address hostname of the postgres server for the catalog DB
5 # @param db_port port of the postgres server for the catalog DB
6 # @param db_name DB name for the catalog DB
7 # @param db_user username for the postgres server for the catalog DB
8 # @param port_dir Port that the director should listen on
9 # @param db_sslca SSL CA store for DB access
10 class bacula::director(
13 String $db_name = 'bacula',
14 String $db_user = 'bacula',
15 String $pool_name = 'bacula',
16 Integer $port_dir = 9101,
17 Optional[String] $db_sslca = undef,
20 # used by e.g. bconsole
21 $director_secret = hkdf('/etc/puppet/secret', "bacula-dir-${::fqdn}")
22 # the RestoreFiles Job needs a Pool. Any valid pool.
23 $some_pool_name = "poolfull-${pool_name}-${bacula::bacula_director_address}"
26 'bacula-director-pgsql',
30 ensure => 'installed',
33 service { 'bacula-director':
37 require => Package['bacula-director-pgsql']
39 dsa_systemd::override { 'bacula-director':
46 exec { 'bacula-director reload':
47 path => '/usr/bin:/usr/sbin:/bin:/sbin',
48 command => 'service bacula-director reload',
52 file { '/etc/bacula/conf.d':
59 source => 'puppet:///files/empty/',
60 notify => Exec['bacula-director reload']
63 file { '/etc/bacula/bacula-dir.conf':
64 content => template('bacula/bacula-dir.conf.erb'),
67 require => Package['bacula-director-pgsql'],
68 notify => Exec['bacula-director reload']
71 file { '/etc/bacula/conf.d/empty.conf':
75 require => Package['bacula-director-pgsql'],
76 notify => Exec['bacula-director reload']
79 Bacula::Director::Client <<| tag == "bacula::to-director::${::fqdn}" |>>
80 Bacula::Director::Client_from_storage<<| tag == "bacula::to-director::${::fqdn}" |>>
82 package { 'bacula-console':
86 file { '/etc/bacula/bconsole.conf':
87 content => template('bacula/bconsole.conf.erb'),
90 require => Package['bacula-console']
93 package { 'python3-psycopg2': ensure => installed }
94 file { '/etc/bacula/scripts/volume-purge-action':
96 source => 'puppet:///modules/bacula/volume-purge-action',
99 file { '/etc/bacula/scripts/volumes-delete-old':
101 source => 'puppet:///modules/bacula/volumes-delete-old',
104 file { '/etc/bacula/storages-list.d':
111 source => 'puppet:///files/empty/',
113 file { '/usr/local/sbin/dsa-bacula-scheduler':
114 source => 'puppet:///modules/bacula/dsa-bacula-scheduler',
118 file { '/etc/cron.d/puppet-bacula-stuff': ensure => absent, }
119 concat::fragment { 'puppet-crontab--bacula-director':
120 target => '/etc/cron.d/puppet-crontab',
122 @daily root chronic /etc/bacula/scripts/volume-purge-action -v
123 @daily root chronic /etc/bacula/scripts/volumes-delete-old -v
124 */3 * * * * root sleep $(( $RANDOM \% 60 )); flock -w 0 -e /usr/local/sbin/dsa-bacula-scheduler /usr/local/sbin/dsa-bacula-scheduler
128 concat { $bacula::bacula_dsa_client_list:
130 concat::fragment { 'bacula-dsa-client-list::header' :
131 target => $bacula::bacula_dsa_client_list,
135 Concat::Fragment <<| tag == $bacula::tag_bacula_dsa_client_list |>>
137 @@ferm::rule::simple { "bacula::director-to-fd::${::fqdn}":
138 tag => "bacula::director-to-fd::${::fqdn}",
139 description => 'Allow bacula-fd from the bacula-director',
140 port => '7', # overridden on collecting
141 saddr => $bacula::public_addresses,
143 @@ferm::rule::simple { "bacula::director-to-storage::${::fqdn}":
144 tag => "bacula::director-to-storage::${::fqdn}",
145 description => 'Allow bacula-storage access from the bacula-director',
146 chain => 'bacula-sd',
147 saddr => $bacula::public_addresses,