2020-11-21 20:46:41 +00:00
|
|
|
from json import loads
|
|
|
|
from os.path import join
|
|
|
|
|
2020-11-10 11:40:12 +00:00
|
|
|
defaults = {
|
|
|
|
'apt': {
|
|
|
|
'repos': {
|
|
|
|
'icinga2': {
|
|
|
|
'items': {
|
|
|
|
'deb http://packages.icinga.com/{os} icinga-{os_release} main',
|
|
|
|
'deb-src http://packages.icinga.com/{os} icinga-{os_release} main',
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2020-11-10 13:26:07 +00:00
|
|
|
'packages': {
|
2020-11-13 12:19:26 +00:00
|
|
|
'icinga2': {},
|
|
|
|
'icinga2-ido-pgsql': {},
|
|
|
|
'icingaweb2': {},
|
|
|
|
'icingaweb2-module-monitoring': {},
|
|
|
|
|
2020-11-10 13:26:07 +00:00
|
|
|
# needed for check_rbl
|
|
|
|
'libdata-validate-ip-perl': {},
|
|
|
|
'libdata-validate-ip-perl': {},
|
|
|
|
'libmonitoring-plugin-perl': {},
|
|
|
|
'libnet-dns-perl': {},
|
|
|
|
'libreadonly-perl': {},
|
|
|
|
}
|
2020-11-10 11:40:12 +00:00
|
|
|
},
|
2020-11-21 09:29:36 +00:00
|
|
|
'icinga2': {
|
|
|
|
'api_users': {
|
|
|
|
'root': repo.vault.password_for(f'{node.name} icinga2 api root'),
|
|
|
|
},
|
|
|
|
},
|
2020-11-21 07:57:46 +00:00
|
|
|
'icingaweb2': {
|
|
|
|
'setup-token': repo.vault.password_for(f'{node.name} icingaweb2 setup-token'),
|
|
|
|
},
|
2020-11-10 11:40:12 +00:00
|
|
|
'postgresql': {
|
|
|
|
'roles': {
|
|
|
|
'icinga2': {
|
|
|
|
'password': repo.vault.password_for(f'{node.name} postgresql icinga2'),
|
|
|
|
},
|
|
|
|
},
|
|
|
|
'databases': {
|
2020-11-21 07:57:46 +00:00
|
|
|
'icingaweb2': {
|
|
|
|
'owner': 'icinga2',
|
|
|
|
},
|
2020-11-10 11:40:12 +00:00
|
|
|
'icinga2': {
|
|
|
|
'owner': 'icinga2',
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
2020-11-21 20:46:41 +00:00
|
|
|
|
|
|
|
@metadata_reactor
|
|
|
|
def add_users_from_json(metadata):
|
|
|
|
with open(join(repo.path, 'users.json'), 'r') as f:
|
|
|
|
json = loads(f.read())
|
|
|
|
|
|
|
|
users = {}
|
|
|
|
for uname, config in json.items():
|
|
|
|
users[uname] = {
|
|
|
|
'email': '',
|
|
|
|
'phone': '',
|
|
|
|
'is_admin': config.get('is_admin', False),
|
|
|
|
}
|
|
|
|
|
|
|
|
if 'email' in config:
|
|
|
|
users[uname]['email'] = repo.vault.decrypt(config['email'])
|
|
|
|
if 'phone' in config:
|
|
|
|
users[uname]['phone'] = repo.vault.decrypt(config['phone'])
|
|
|
|
|
|
|
|
return {
|
|
|
|
'icinga2': {
|
|
|
|
'icinga_users': users,
|
|
|
|
},
|
|
|
|
}
|