Create client name and secret in the fd and ship
[mirror/dsa-puppet.git] / modules / bacula / manifests / init.pp
1 # bacula class -- defines all the variables we care about in our bacula deployment
2 #
3 # @param public_addresses this host's public IP addresses.  The ones it connects out from and is reachable from outsite.
4 class bacula (
5   String  $bacula_operator_email      = 'bacula-reports@admin.debian.org',
6   String  $bacula_director_name       = 'debian-dir',
7   String  $bacula_storage_name        = 'debian-sd',
8   String  $bacula_monitor_name        = 'debian-mon',
9
10   String  $bacula_director_address    = 'dinis.debian.org',
11   String  $bacula_storage_address     = 'storace.debian.org',
12
13   String  $bacula_db_secret           = hkdf('/etc/puppet/secret', "bacula-db-${::hostname}"),
14   String  $bacula_monitor_secret      = hkdf('/etc/puppet/secret', "bacula-monitor-${bacula_director_name}"),
15
16   String  $bacula_ca_path             = '/etc/ssl/debian/certs/ca.crt',
17   String  $bacula_ssl_client_cert     = '/etc/ssl/debian/certs/thishost.crt',
18   String  $bacula_ssl_client_key      = '/etc/ssl/private/thishost.key',
19   String  $bacula_ssl_server_cert     = '/etc/ssl/debian/certs/thishost-server.crt',
20   String  $bacula_ssl_server_key      = '/etc/ssl/private/thishost-server.key',
21
22   String  $bacula_dsa_client_list     = '/etc/bacula/dsa-clients',
23   String  $tag_bacula_dsa_client_list = 'bacula::dsa::clientlist',
24
25   Array[Stdlib::IP::Address] $public_addresses = $base::public_addresses,
26 ) {
27   file { '/usr/local/sbin/bacula-idle-restart':
28     mode   => '0555',
29     source => 'puppet:///modules/bacula/bacula-idle-restart',
30   }
31 }