diff options
Diffstat (limited to 'puppet/modules')
-rw-r--r-- | puppet/modules/site_stunnel/manifests/clients.pp (renamed from puppet/modules/site_webapp/manifests/couchdb_stunnel/clients.pp) | 21 | ||||
-rw-r--r-- | puppet/modules/site_stunnel/manifests/setup.pp (renamed from puppet/modules/site_webapp/manifests/couchdb_stunnel.pp) | 17 | ||||
-rw-r--r-- | puppet/modules/site_webapp/manifests/couchdb.pp | 21 |
3 files changed, 37 insertions, 22 deletions
diff --git a/puppet/modules/site_webapp/manifests/couchdb_stunnel/clients.pp b/puppet/modules/site_stunnel/manifests/clients.pp index eac43b08..28ed6d3c 100644 --- a/puppet/modules/site_webapp/manifests/couchdb_stunnel/clients.pp +++ b/puppet/modules/site_stunnel/manifests/clients.pp @@ -1,6 +1,21 @@ -define site_webapp::couchdb_stunnel::clients - ( $accept_port, $connect, $client, $cafile, $key, $cert, - $verify, $pid = $name, $rndfile, $debuglevel ) { +define site_stunnel::clients ( + $accept_port, + $connect, + $client = true, + $cafile, + $key, + $cert, + $verify = '2', + $pid = $name, + $rndfile = '/var/lib/stunnel4/.rnd', + $debuglevel = '4' ) { + + $couchdb_stunnel_client_defaults = { + 'cafile' => $ca_path, + 'key' => $key_path, + 'cert' => $cert_path, + } + stunnel::service { $name: accept => "127.0.0.1:${accept_port}", diff --git a/puppet/modules/site_webapp/manifests/couchdb_stunnel.pp b/puppet/modules/site_stunnel/manifests/setup.pp index 325b18ee..a6384a6e 100644 --- a/puppet/modules/site_webapp/manifests/couchdb_stunnel.pp +++ b/puppet/modules/site_stunnel/manifests/setup.pp @@ -1,9 +1,8 @@ -class site_webapp::couchdb_stunnel ($key, $cert, $ca) { +class site_stunnel::setup ($cert_name, $key, $cert, $ca) { include x509::variables include site_stunnel - $cert_name = 'leap_couchdb' $ca_name = 'leap_ca' $ca_path = "${x509::variables::local_CAs}/${ca_name}.crt" $cert_path = "${x509::variables::certs}/${cert_name}.crt" @@ -24,20 +23,8 @@ class site_webapp::couchdb_stunnel ($key, $cert, $ca) { x509::ca { $ca_name: content => $ca, - notify => Service['stunnel']; - } - - $couchdb_stunnel_client_defaults = { - 'client' => true, - 'cafile' => $ca_path, - 'key' => $key_path, - 'cert' => $cert_path, - 'verify' => '2', - 'rndfile' => '/var/lib/stunnel4/.rnd', - 'debuglevel' => '4' + notify => Service['stunnel']; } - create_resources(site_webapp::couchdb_stunnel::clients, hiera('stunnel'), $couchdb_stunnel_client_defaults) - } diff --git a/puppet/modules/site_webapp/manifests/couchdb.pp b/puppet/modules/site_webapp/manifests/couchdb.pp index ef61aeb6..e45691c1 100644 --- a/puppet/modules/site_webapp/manifests/couchdb.pp +++ b/puppet/modules/site_webapp/manifests/couchdb.pp @@ -33,10 +33,11 @@ class site_webapp::couchdb { mode => '0744'; } - class { 'site_webapp::couchdb_stunnel': - key => $key, - cert => $cert, - ca => $ca + class { 'site_stunnel::setup': + cert_name => 'leap_couchdb', + key => $key, + cert => $cert, + ca => $ca } exec { 'migrate_design_documents': @@ -45,4 +46,16 @@ class site_webapp::couchdb { require => Exec['bundler_update'], notify => Service['apache']; } + + $couchdb_stunnel_client_defaults = { + 'client' => true, + 'cafile' => $ca_path, + 'key' => $key_path, + 'cert' => $cert_path, + 'verify' => '2', + 'rndfile' => '/var/lib/stunnel4/.rnd', + 'debuglevel' => '4' + } + + create_resources(site_stunnel::clients, hiera('stunnel'), $couchdb_stunnel_client_defaults) } |