Recommit for updates in build 42

This commit is contained in:
Jenkins Server
2026-03-15 15:05:49 +01:00
parent 0a31c8297e
commit 0e9740a5ab
4 changed files with 58 additions and 10 deletions

View File

@@ -78,7 +78,7 @@
</li><li> </li><li>
<p><a href="#managing-check-commands">Managing Check Commands</a></p> <p><a href="#managing-check-commands">Managing Check Commands</a></p>
</li><li> </li><li>
<p><a href="#managing-tls-serts">managing TLS serts</a></p> <p><a href="#managing-tls-certificates">managing TLS certificates</a></p>
</li><li> </li><li>
<p><a href="#selinux">SELINUX</a></p> <p><a href="#selinux">SELINUX</a></p>
</li><li> </li><li>
@@ -191,7 +191,7 @@
<p>It is very recommendable to define such commands directly within Puppet modules or profiles, so any node running the particular service controlled by the module will automatically get the required check commands defined as well, while nodes not running the service also do not contain the command check. The same then is true for Nagios checks, so you would have both the NRPE command definition and the Nagios check contained in Puppet modules or profiles to have it in one location.</p> <p>It is very recommendable to define such commands directly within Puppet modules or profiles, so any node running the particular service controlled by the module will automatically get the required check commands defined as well, while nodes not running the service also do not contain the command check. The same then is true for Nagios checks, so you would have both the NRPE command definition and the Nagios check contained in Puppet modules or profiles to have it in one location.</p>
<h2 id="label-managing+TLS+serts">managing TLS serts</h2> <h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>

View File

@@ -78,7 +78,7 @@
</li><li> </li><li>
<p><a href="#managing-check-commands">Managing Check Commands</a></p> <p><a href="#managing-check-commands">Managing Check Commands</a></p>
</li><li> </li><li>
<p><a href="#managing-tls-serts">managing TLS serts</a></p> <p><a href="#managing-tls-certificates">managing TLS certificates</a></p>
</li><li> </li><li>
<p><a href="#selinux">SELINUX</a></p> <p><a href="#selinux">SELINUX</a></p>
</li><li> </li><li>
@@ -191,7 +191,7 @@
<p>It is very recommendable to define such commands directly within Puppet modules or profiles, so any node running the particular service controlled by the module will automatically get the required check commands defined as well, while nodes not running the service also do not contain the command check. The same then is true for Nagios checks, so you would have both the NRPE command definition and the Nagios check contained in Puppet modules or profiles to have it in one location.</p> <p>It is very recommendable to define such commands directly within Puppet modules or profiles, so any node running the particular service controlled by the module will automatically get the required check commands defined as well, while nodes not running the service also do not contain the command check. The same then is true for Nagios checks, so you would have both the NRPE command definition and the Nagios check contained in Puppet modules or profiles to have it in one location.</p>
<h2 id="label-managing+TLS+serts">managing TLS serts</h2> <h2 id="label-managing+TLS+certificates">managing TLS certificates</h2>
<h2 id="label-SELINUX">SELINUX</h2> <h2 id="label-SELINUX">SELINUX</h2>

View File

@@ -196,7 +196,19 @@
98 98
99 99
100 100
101</pre> 101
102
103
104
105
106
107
108
109
110
111
112
113</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span> <pre class="code"><span class="info file"># File 'manifests/main/files.pp', line 6</span>
@@ -294,6 +306,18 @@ class confdroid_nrpe::main::files (
seluser =&gt; system_u, seluser =&gt; system_u,
content =&gt; template($ne_ssl_privatekey_erb), content =&gt; template($ne_ssl_privatekey_erb),
} }
file { $ne_ssl_ca_cert_file:
ensure =&gt; file,
path =&gt; $ne_ssl_ca_cert_file,
owner =&gt; &#39;root&#39;,
group =&gt; &#39;root&#39;,
mode =&gt; &#39;0644&#39;,
selrange =&gt; s0,
selrole =&gt; object_r,
seltype =&gt; cert_t,
seluser =&gt; system_u,
content =&gt; template($ne_ssl_ca_cert_erb),
}
} }
} }
}</pre> }</pre>

View File

@@ -777,6 +777,24 @@ inherited by all classes except defines.
&mdash; &mdash;
<div class='inline'> <div class='inline'>
<p>Optional parameter to specify the content of the nagios server ssl private key. This is used for the nagios server private key and has to be provided via Hiera or ENC. Must be specified if SSL is enabled.</p> <p>Optional parameter to specify the content of the nagios server ssl private key. This is used for the nagios server private key and has to be provided via Hiera or ENC. Must be specified if SSL is enabled.</p>
</div>
</li>
<li>
<span class='name'>ne_ssl_ca_cert_pem</span>
<span class='type'>(<tt>Optional[String]</tt>)</span>
<em class="default">(defaults to: <tt>undef</tt>)</em>
&mdash;
<div class='inline'>
<p>Optional parameter to specify the content of the CA certificate. This is used for the CA certificate and has to be provided via Hiera or ENC. Must be specified if SSL is enabled.</p>
</div> </div>
</li> </li>
@@ -799,9 +817,6 @@ inherited by all classes except defines.
<pre class="lines"> <pre class="lines">
86
87
88
89 89
90 90
91 91
@@ -890,10 +905,16 @@ inherited by all classes except defines.
174 174
175 175
176 176
177</pre> 177
178
179
180
181
182
183</pre>
</td> </td>
<td> <td>
<pre class="code"><span class="info file"># File 'manifests/params.pp', line 86</span> <pre class="code"><span class="info file"># File 'manifests/params.pp', line 89</span>
class confdroid_nrpe::params ( class confdroid_nrpe::params (
@@ -935,6 +956,7 @@ class confdroid_nrpe::params (
String $ne_include_file = &#39;&#39;, String $ne_include_file = &#39;&#39;,
Optional[String] $ne_ssl_cert_pem = undef, Optional[String] $ne_ssl_cert_pem = undef,
Optional[String] $ne_ssl_privatekey_pem = undef, Optional[String] $ne_ssl_privatekey_pem = undef,
Optional[String] $ne_ssl_ca_cert_pem = undef,
# nrpe.conf # nrpe.conf
String $ne_ssl_opts = &#39;&#39;, String $ne_ssl_opts = &#39;&#39;,
@@ -983,6 +1005,8 @@ class confdroid_nrpe::params (
$ne_ssl_cert_erb = &#39;confdroid_nrpe/ssl_cert.erb&#39; $ne_ssl_cert_erb = &#39;confdroid_nrpe/ssl_cert.erb&#39;
$ne_ssl_privatekey_file = &quot;/etc/pki/tls/private/${fqdn}.key.pem&quot; $ne_ssl_privatekey_file = &quot;/etc/pki/tls/private/${fqdn}.key.pem&quot;
$ne_ssl_privatekey_erb = &#39;confdroid_nrpe/ssl_privatekey.erb&#39; $ne_ssl_privatekey_erb = &#39;confdroid_nrpe/ssl_privatekey.erb&#39;
$ne_ssl_ca_cert_file = &quot;/etc/pki/tls/certs/${fqdn}-ca-chain.crt.pem&quot;
$ne_ssl_ca_cert_erb = &#39;confdroid_nrpe/ssl_ca_cert.erb&#39;
# includes must be last # includes must be last
include confdroid_nrpe::main::config include confdroid_nrpe::main::config