bastelfreak
02/23/2023, 9:05 PMSlackbot
02/23/2023, 9:16 PMbastelfreak
02/23/2023, 9:17 PMCVQuesty
02/23/2023, 9:22 PMDr Bunsen Honeydew
02/23/2023, 9:45 PMSlackbot
02/24/2023, 11:21 AMMarty Ewings
02/24/2023, 11:49 AMBrian Schonecker
02/24/2023, 12:59 PMfe80
02/24/2023, 1:06 PMSlackbot
02/24/2023, 1:57 PMcruelsmith
02/24/2023, 5:35 PMSensitive(Sensitive('Password')) work or does it just return [redacted] ?
Background is: https://github.com/puppetlabs/puppetlabs-postgresql/issues/1402#issuecomment-1444090897cruelsmith
02/24/2023, 5:35 PMSensitive(Sensitive('Password')) work or does it just return [redacted] ?
Background is: https://github.com/puppetlabs/puppetlabs-postgresql/issues/1402#issuecomment-1444090897natemccurdy
02/24/2023, 5:45 PMpuppet apply.
Sensitive in Sensitive does work, but you have to understand how to use it.
$ puppet apply sensitive.pp
Notice: Scope(Class[main]): One layer deep:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]): Sensitive[String]
Notice: Scope(Class[main]): helloworld
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Two layers deep:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]): Sensitive[String]
Notice: Scope(Class[main]): helloworld
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Unwrapping the inner layer isn't enough when using two layers:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Unwrapping the outer layer will unwrap all nested Sensitive layers:
Notice: Scope(Class[main]): helloworldnatemccurdy
02/24/2023, 5:45 PMpuppet apply.
Sensitive in Sensitive does work, but you have to understand how to use it.
$ puppet apply sensitive.pp
Notice: Scope(Class[main]): One layer deep:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]): Sensitive[String]
Notice: Scope(Class[main]): helloworld
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Two layers deep:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]): Sensitive[String]
Notice: Scope(Class[main]): helloworld
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Unwrapping the inner layer isn't enough when using two layers:
Notice: Scope(Class[main]): Sensitive [value redacted]
Notice: Scope(Class[main]):
Notice: Scope(Class[main]): Unwrapping the outer layer will unwrap all nested Sensitive layers:
Notice: Scope(Class[main]): helloworldnatemccurdy
02/24/2023, 5:48 PMSensitive[String].... which really means it's just one layer.
I'm pretty sure that applying Sensitive to something that's already Sensitive is a noop.Slackbot
02/24/2023, 5:55 PMnatemccurdy
02/24/2023, 6:15 PMcruelsmith
02/24/2023, 6:21 PMSlackbot
02/24/2023, 6:28 PMCorporate Gadfly
02/24/2023, 7:53 PMfacts : {
blocklist : [
"file system",
"load_averages",
"identity",
"memory.system.capacity",
"memory.system.used",
"memory.system.used_bytes",
"memory.system.available",
"memory.system.available_bytes",
"memory.swap.capacity",
"memory.swap.used",
"memory.swap.used_bytes",
"memory.swap.available",
"memory.swap.available_bytes",
"system_uptime",
]
}
I get:
# facter -p -j | jq '.partitions."/dev/sda1".size'
null
With file system removed from blocklist, I get a valid value:
# facter -p -j | jq '.partitions."/dev/sda1".size'
"1.00 GiB"
Are you able to recreate?Corporate Gadfly
02/24/2023, 7:58 PM...
file system
- mountpoints
- filesystems
- partitions
...vchepkov
02/24/2023, 8:06 PMCorey Hickey
02/24/2023, 8:46 PM$ RUBYLIB=lib bin/facter -p -j -c facter.gadfly.conf | jq '.partitions."/dev/sda1".size'
"1.00 GiB"
If I remove the -p, then the fact is indeed blocked (and if I subsequently remove the file system blockgroup from the config, the fact comes back, so it's not as if -p is necessary to generate the fact).
In any case, I had been trying to take puppet out of the equation. I wanted to determine if it is possible to configure facter to block an arbitrary fact that is not part of a built-in blocklist. I guess I chose poorly with that fact as an example.
My eventual goal is to block ec2_metadata.managed-ssh-keys.signer-cert, but I can't as easily test facter from git on a host that actually has that fact.Corey Hickey
02/24/2023, 9:27 PMec2_metadata but not anything below that. The ec2_metadata tree has other facts which are useful and not huge, so I don't want to block the whole thing.Slackbot
02/25/2023, 6:06 PMcruelsmith
02/25/2023, 6:09 PMpostgresql::postgresql_password defines two required_param and three optional_param with also default values. That keeped me thinking i can do that in .pp to skip set the third parameter to be set and only set the fourth one.
postgresql::postgresql_password('user', 'password', undef, 'md5')
But that result in spec errors that the third parameter does not match the type and also default value is ignored for that parameter.
The parameter type could be changed to Optional[...] but still the default value gets not applied.cruelsmith
02/25/2023, 6:11 PMpostgresql::postgresql_password defines two required_param and three optional_param with also default values. That keeped me thinking i can do that in .pp to skip set the third parameter to be set and only set the fourth one.
postgresql::postgresql_password('user', 'password', undef, 'md5')
But that result in spec errors that the third parameter does not match the type and also default value is ignored for that parameter.
The parameter type could be changed to Optional[...] but still the default value gets not applied.
So it that kind of wanted that the function itself must check for Undef conversion to nil?cruelsmith
02/25/2023, 6:21 PMcruelsmith
02/25/2023, 6:21 PMhelindbe
02/25/2023, 6:23 PM