class { '::salsa::redis': } ->
class { '::salsa::packages': } ->
class { '::salsa::database': } ->
+ class { '::salsa::web': } ->
anchor { 'salsa::end': }
# userdir-ldap users get their home in /home
owner => $salsa::user,
group => $salsa::group,
}
+ file { "/home/${salsa::webhook_user}":
+ ensure => link,
+ target => $salsa::webhook_user_home,
+ }
+ file { $salsa::webhook_user_home:
+ ensure => directory,
+ mode => '0755',
+ owner => $salsa::webhook_user,
+ group => $salsa::webhook_user,
+ }
+
file { "${salsa::home}/.credentials.yaml":
mode => '0400',
group => $salsa::group,
content => @("EOF"),
---
+ # This file is maintained by puppet.
+ # base secret that gitlab encrypts the DB with
+ secret: "${salsa::secret}"
database:
name: "${salsa::db_name}"
role: "${salsa::db_role}"
password: "${salsa::mail_password}"
| EOF
}
-
- ssl::service { $servicename:
- # notify => Exec['service apache2 reload'],
- key => true,
+ file { "${salsa::home}/.credentials-manual.yaml":
+ mode => '0400',
+ owner => $salsa::user,
+ group => $salsa::group,
+ content => @("EOF"),
+ ---
+ # This file was put in place by puppet, but it won't overwrite it.
+ # Please fill in from dsa-passwords/services-salsa
+ # mastersecret: "swordfish"
+ | EOF
+ replace => false,
+ }
+ file { "/var/lib/systemd/linger/git":
+ ensure => present,
+ }
+ file { "/var/lib/systemd/linger/${salsa::webhook_user}":
+ ensure => present,
+ }
+ file { "/etc/ssh/userkeys/git":
+ ensure => link,
+ target => "${salsa::home}/.ssh/authorized_keys",
+ }
+ # pages
+ file { "/etc/network/interfaces.d/pages.debian.net.conf":
+ content => @("EOF"),
+ iface eth0 inet static
+ address 209.87.16.45/24
+ iface eth0 inet6 static
+ address 2607:f8f0:614:1::1274:45/64
+ preferred-lifetime 0
+ | EOF
+ notify => Exec['service networking reload'],
+ }
+ exec { 'service networking reload':
+ refreshonly => true,
}
}