Fix linger setup to use variable
[mirror/dsa-puppet.git] / modules / salsa / manifests / init.pp
index 7a992ea..be5d10f 100644 (file)
@@ -7,6 +7,7 @@ class salsa inherits salsa::params {
        class { '::salsa::redis': } ->
        class { '::salsa::packages': } ->
        class { '::salsa::database': } ->
+       class { '::salsa::web': } ->
        anchor { 'salsa::end': }
 
        # userdir-ldap users get their home in /home
@@ -20,6 +21,17 @@ class salsa inherits salsa::params {
                owner  => $salsa::user,
                group  => $salsa::group,
        }
+       file { "/home/${salsa::webhook_user}":
+               ensure => link,
+               target => $salsa::webhook_user_home,
+       }
+       file { $salsa::webhook_user_home:
+               ensure => directory,
+               mode   => '0755',
+               owner  => $salsa::webhook_user,
+               group  => $salsa::webhook_user,
+       }
+
 
        file { "${salsa::home}/.credentials.yaml":
                mode => '0400',
@@ -54,9 +66,25 @@ class salsa inherits salsa::params {
        file { "/var/lib/systemd/linger/git":
                ensure => present,
        }
-
-       ssl::service { $servicename:
-               # notify  => Exec['service apache2 reload'],
-               key => true,
+       file { "/var/lib/systemd/linger/${salsa::webhook_user}":
+               ensure => present,
+       }
+       file { "/etc/ssh/userkeys/git":
+               ensure => link,
+               target => "${salsa::home}/.ssh/authorized_keys",
+       }
+       # pages
+       file { "/etc/network/interfaces.d/pages.debian.net.conf":
+               content  => @("EOF"),
+                               iface eth0 inet static
+                                   address 209.87.16.45/24
+                               iface eth0 inet6 static
+                                   address 2607:f8f0:614:1::1274:45/64
+                                   preferred-lifetime 0
+                               | EOF
+               notify => Exec['service networking reload'],
+       }
+       exec { 'service networking reload':
+               refreshonly => true,
        }
 }