control-repo/README.md

199 lines
7.2 KiB
Markdown
Raw Normal View History

2015-05-26 17:00:02 +00:00
# Before Starting:
This control repo and the steps below are intended to be used during a new installation of PE.
2015-05-26 17:00:02 +00:00
If you intend to use it on an existing installation of PE then you'll have to figure out some of the steps on your own and be warned that if you've already written or downloaded modules when you start using r10k it will remove all of the existing modules and replace them with what you define in your Puppetfile. Please copy or move your existing modules to another directory to ensure you do not lose any work you've already started.
2015-05-26 17:00:02 +00:00
2015-09-24 23:03:26 +00:00
## Setup a Trusted Fact On Your PE Master
2015-09-24 23:03:26 +00:00
This control repository is setup to manage certain portions of your PE installation for you if you create a trusted fact called `pp_role`. In order to do so, lay down a file that looks exactly like the below in `/etc/puppetlabs/puppet/csr_attributes.yaml`
```
---
extension_requests:
#pp_role
1.3.6.1.4.1.34380.1.1.13: 'all_in_one_pe'
```
2015-09-24 23:03:26 +00:00
### If You Have Not Installed PE
2015-09-24 23:03:26 +00:00
Good then you can proceed forward and the trusted fact will be used when you get to the install step.
### If You Have Already Installed PE
Trusted facts are created at the time a CSR is generated. So, we need to regenerate the certificate on the master for the above trusted fact to be created.
Follow this document to regenerate the certificate on your master.
2015-09-24 23:03:26 +00:00
http://docs.puppetlabs.com/pe/latest/regenerate_certs_master.html
2015-09-24 23:03:26 +00:00
##Copy This Repo Into Your Own Git Server
###Gitlab
1. Install Gitlab
- https://about.gitlab.com/downloads/
2. After Gitlab is installed you may sign if with the `root` user and password `5iveL!fe`
2015-09-24 23:03:26 +00:00
3. Make an user for yourself
2015-09-24 23:03:26 +00:00
4. Make an ssh key to link with your user. Youll want to do this on the machine you intend to edit code from ( most likely not your puppet master but your local workstation / laptop )
- http://doc.gitlab.com/ce/ssh/README.html
- https://help.github.com/articles/generating-ssh-keys/
2015-09-24 23:03:26 +00:00
5. Create a group called `puppet` ( this is case sensitive )
- http://doc.gitlab.com/ce/workflow/groups.html
2015-09-24 23:03:26 +00:00
6. Create a user called `r10k_api_user` and add them to the `puppet` group
- From the landing page, select groups
- Choose the puppet group
- In the left hand pane, select memembers
- Add the `r10k_api_user` with `master` permissions
2015-09-24 23:03:26 +00:00
7. Add your user to the `puppet` group as well
2015-09-24 23:03:26 +00:00
7. Create a project called `control-repo` and set the Namespace to be the `puppet` group
2015-09-24 23:03:26 +00:00
8. Logout of root and login as the `r10k_api_user`
- Go to profile settings -> account ( https://<your_gitlab_server>/profile/account )
- Copy the api token
9. Clone this control repository to your laptop/workstation
- `git clone https://github.com/npwalker/control-repo.git`
- `cd control-repo`
2015-09-29 18:09:54 +00:00
10. `git mv hieradata/nodes/example-puppet-master.yaml hieradata/nodes/<fqdn_of_your_puppet_master>.yaml`
2015-09-24 23:03:26 +00:00
- Open `hieradata/nodes/<fqdn_of_your_puppet_master>.yaml`
- edit `gms_api_token` to be your api token
- edit `git_management_system` to be 'gitlab'
2015-09-29 18:09:54 +00:00
- edit the `gms_server_url`
11. `git add hieradata/nodes/<fqdn_of_your_puppet_master>.yaml`
2015-09-29 18:09:54 +00:00
11. `git commit -m "renaming example-puppet-master.yaml"`
2015-09-24 23:03:26 +00:00
11. Rename my repository as the upstream remote
- `git remote rename origin upstream`
2015-09-24 23:03:26 +00:00
12. Add your internal repository as the origin remote
- `git remote add origin <url of your repository from step 4>`
13. `git branch --set-upstream-to origin/production`
2015-09-24 23:03:26 +00:00
13. Push the production branch of the repository from your machine up to your git server
- `git push origin production`
2015-09-24 23:03:26 +00:00
###Stash
2015-09-24 23:03:26 +00:00
###Github
2015-09-24 23:03:26 +00:00
###The General Idea - Not Specific to GMS
2015-09-24 23:03:26 +00:00
1. Make an user in your internal git server for yourself
2015-09-24 23:03:26 +00:00
2. Make an ssh key to link with your user. Youll want to do this on the machine you intend to edit code from ( most likely not your puppet master but your local workstation / laptop )
2015-09-24 23:03:26 +00:00
- https://help.github.com/articles/generating-ssh-keys/
2015-09-24 23:03:26 +00:00
3. Create a group or organization called "puppet"
2015-08-18 23:09:53 +00:00
2015-09-24 23:03:26 +00:00
4. Create a repository in your git server called control-repo
2015-09-24 23:03:26 +00:00
4. Clone this control repository to your laptop/workstation
- `git clone https://github.com/npwalker/control-repo.git`
- `cd control-repo`
2015-09-24 23:03:26 +00:00
5. Rename my repository as the upstream remote
- `git remote rename origin upstream`
2015-09-24 23:03:26 +00:00
6. Add your internal repository as the origin remote
- `git remote add origin <url of your repository from step 4>`
2015-09-24 23:03:26 +00:00
7. Push the production branch of the repository from your machine up to your git server
- `git push origin production`
2015-08-18 23:09:53 +00:00
8. Find the url to your internal repo. This is usually on the front page of the repo
2015-09-24 23:03:26 +00:00
9. Add the repo as a remote
- git remote add origin git@your-git-server:puppet/control-repo.git
2015-09-24 23:03:26 +00:00
10. Push the repository from your machine up to your git server
2015-09-24 23:03:26 +00:00
- git push origin production
2015-09-24 23:03:26 +00:00
##Configure PE to Use the Control-Repo
2015-09-24 23:03:26 +00:00
###Install PE
2015-09-24 23:03:26 +00:00
1. Download the latest version of the PE installer for your platform and copy it to your master
- https://puppetlabs.com/download-puppet-enterprise
2. Expand the tarball and `cd` into the directory
3. Run `puppet-enterprise-installer` to install
2015-09-24 23:03:26 +00:00
If you run into any issues or have more questions about the installer you can see our docs here:
2015-09-24 23:03:26 +00:00
http://docs.puppetlabs.com/pe/latest/install_basic.html
##Get the Control-Repo Deployed On Your Master
At this point you have my control-repo code deployed into your git server. However, we have one final challenge getting that code onto your puppet master. In the end state the master will pull code from the git server via r10k, however, at this moment your puppet master doesn't have credentials to get code from the git server.
So, we'll set up a deploy key in the git server that will allow a ssh-key we make to deploy the code and configure everything else.
1. On your puppet master, make an ssh key for r10k to connect to gitlab
- `/usr/bin/ssh-keygen -t rsa -b 2048 -C 'r10k' -f /root/.ssh/r10k_rsa -q -N ''`
- http://doc.gitlab.com/ce/ssh/README.html
- https://help.github.com/articles/generating-ssh-keys/
2. Create a deploy key on the `control-repo` project in Gitlab
- paste in the public key from above
3. Follow https://docs.puppetlabs.com/pe/latest/r10k_config_console.html
- The remote is on the front page of the project in the gitlab UI
- git_settings should be:
- `{"provider": "rugged",
"private_key": "/root/.ssh/r10k_rsa"}`
3. Run `puppet agent -t`
- Expect to see changes to `r10k.yaml`
3. Run `r10k deploy environment -pv`
4. Run `puppet agent -t`
2015-09-24 23:03:26 +00:00
### Update Your Existing Install To Point To The Control Repository
2015-09-24 23:03:26 +00:00
https://docs.puppetlabs.com/pe/latest/r10k_config_console.html
## Run r10k
2015-09-29 18:09:54 +00:00
1. Run `r10k deploy environment -pv` and watch it install the modules from your Puppetfile
2015-01-15 01:17:58 +00:00
2015-09-24 23:03:26 +00:00
----
#Miscellaneous
## If You Want to Install Pointing To This Repo on Github
### Setting Up Gitlab
1. Install Gitlab on a server by specifying the following trusted fact on the soon-to-be Gitlab server and then [install the PE agent](http://docs.puppetlabs.com/pe/latest/install_agents.html#using-the-puppet-agent-package-installation-script).
```
---
extension_requests:
#pp_role
1.3.6.1.4.1.34380.1.1.13: 'gitlab'
```
### Setting up Github
Not yet completed.
### Setting up Stash
Not yet completed.
#TODO
Flush out generating an answer file and then appending extra answers onto the end of it.