https://www.puppet.com/community logo
Join Slack
Powered by
# puppet
  • b

    bastelfreak

    02/23/2023, 9:05 PM
    ah 😄
  • s

    Slackbot

    02/23/2023, 9:16 PM
    This message was deleted.
    y
    c
    b
    • 4
    • 7
  • b

    bastelfreak

    02/23/2023, 9:17 PM
    tracks all his tickets.puppetlabs.com issues
    😏 1
  • c

    CVQuesty

    02/23/2023, 9:22 PM
    I’m talking about my own repos in GitHub… not necessarily opened tickets with Pup
  • d

    Dr Bunsen Honeydew

    02/23/2023, 9:45 PM
    ☕ 🧑‍🏫PE Console is about to start up in #CFD8Z9A4T
  • s

    Slackbot

    02/24/2023, 11:21 AM
    This message was deleted.
    m
    y
    +3
    • 6
    • 19
  • m

    Marty Ewings

    02/24/2023, 11:49 AM
    ah well, i would go with trusted facts so someone cant impersonate the secret, but then again if its for lab and there is a vault in prod, who cares,
  • b

    Brian Schonecker

    02/24/2023, 12:59 PM
    I figure that even though I'm a development team of one I should try to behave as if I had other people working on the same project.
  • f

    fe80

    02/24/2023, 1:06 PM
    https://github.com/duritong/trocla https://github.com/duritong/puppet-trocla
  • s

    Slackbot

    02/24/2023, 1:57 PM
    This message was deleted.
    s
    a
    +2
    • 5
    • 7
  • c

    cruelsmith

    02/24/2023, 5:35 PM
    Hi, have a Question about the Sensitive Data handling. What happens, wenn we add a Sensitive in a Sensitive? Like does
    Sensitive(Sensitive('Password'))
    work or does it just return
    [redacted]
    ? Background is: https://github.com/puppetlabs/puppetlabs-postgresql/issues/1402#issuecomment-1444090897
  • c

    cruelsmith

    02/24/2023, 5:35 PM
    Hi, have a Question about the Sensitive Data handling. What happens, wenn we add a Sensitive in a Sensitive? Like does
    Sensitive(Sensitive('Password'))
    work or does it just return
    [redacted]
    ? Background is: https://github.com/puppetlabs/puppetlabs-postgresql/issues/1402#issuecomment-1444090897
  • n

    natemccurdy

    02/24/2023, 5:45 PM
    When in doubt, test with
    puppet apply
    . Sensitive in Sensitive does work, but you have to understand how to use it.
    Copy code
    $ puppet apply sensitive.pp
    Notice: Scope(Class[main]): One layer deep:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]): Sensitive[String]
    Notice: Scope(Class[main]): helloworld
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Two layers deep:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]): Sensitive[String]
    Notice: Scope(Class[main]): helloworld
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Unwrapping the inner layer isn't enough when using two layers:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Unwrapping the outer layer will unwrap all nested Sensitive layers:
    Notice: Scope(Class[main]): helloworld
    sensitive.pp
  • n

    natemccurdy

    02/24/2023, 5:45 PM
    When in doubt, test with
    puppet apply
    . Sensitive in Sensitive does work, but you have to understand how to use it.
    Copy code
    $ puppet apply sensitive.pp
    Notice: Scope(Class[main]): One layer deep:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]): Sensitive[String]
    Notice: Scope(Class[main]): helloworld
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Two layers deep:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]): Sensitive[String]
    Notice: Scope(Class[main]): helloworld
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Unwrapping the inner layer isn't enough when using two layers:
    Notice: Scope(Class[main]): Sensitive [value redacted]
    Notice: Scope(Class[main]):
    Notice: Scope(Class[main]): Unwrapping the outer layer will unwrap all nested Sensitive layers:
    Notice: Scope(Class[main]): helloworld
  • n

    natemccurdy

    02/24/2023, 5:48 PM
    Also, notice the data type of the two-layer Sensitive example. It's still just
    Sensitive[String]
    .... which really means it's just one layer. I'm pretty sure that applying
    Sensitive
    to something that's already Sensitive is a noop.
  • s

    Slackbot

    02/24/2023, 5:55 PM
    This message was deleted.
    n
    c
    • 3
    • 3
  • n

    natemccurdy

    02/24/2023, 6:15 PM
    message has been deleted
  • c

    cruelsmith

    02/24/2023, 6:21 PM
    Already the merge of the Sensitive is not allowed unless it unwrapped.
  • s

    Slackbot

    02/24/2023, 6:28 PM
    This message was deleted.
    c
    v
    +2
    • 5
    • 47
  • c

    Corporate Gadfly

    02/24/2023, 7:53 PM
    @Corey Hickey: I don't know the exact mechanics, but here's a starting point, to get the discussion rolling. This is my usual `facter.conf`:
    Copy code
    facts : {
      blocklist : [
        "file system",
        "load_averages",
        "identity",
        "memory.system.capacity",
        "memory.system.used",
        "memory.system.used_bytes",
        "memory.system.available",
        "memory.system.available_bytes",
        "memory.swap.capacity",
        "memory.swap.used",
        "memory.swap.used_bytes",
        "memory.swap.available",
        "memory.swap.available_bytes",
        "system_uptime",
      ]
    }
    I get:
    Copy code
    # facter -p -j | jq '.partitions."/dev/sda1".size'
    null
    With
    file system
    removed from
    blocklist
    , I get a valid value:
    Copy code
    # facter -p -j | jq '.partitions."/dev/sda1".size'
    "1.00 GiB"
    Are you able to recreate?
  • c

    Corporate Gadfly

    02/24/2023, 7:58 PM
    Snippet from output of `facter --list-block-groups`:
    Copy code
    ...
    file system
    - mountpoints
    - filesystems
    - partitions
    ...
  • v

    vchepkov

    02/24/2023, 8:06 PM
    message has been deleted
  • c

    Corey Hickey

    02/24/2023, 8:46 PM
    @Corporate Gadfly I tested with your config file.
    Copy code
    $ RUBYLIB=lib bin/facter -p -j -c facter.gadfly.conf | jq '.partitions."/dev/sda1".size'
    "1.00 GiB"
    If I remove the
    -p
    , then the fact is indeed blocked (and if I subsequently remove the
    file system
    blockgroup from the config, the fact comes back, so it's not as if
    -p
    is necessary to generate the fact). In any case, I had been trying to take puppet out of the equation. I wanted to determine if it is possible to configure facter to block an arbitrary fact that is not part of a built-in blocklist. I guess I chose poorly with that fact as an example. My eventual goal is to block
    ec2_metadata.managed-ssh-keys.signer-cert
    , but I can't as easily test facter from git on a host that actually has that fact.
  • c

    Corey Hickey

    02/24/2023, 9:27 PM
    Yes, likewise, I can block
    ec2_metadata
    but not anything below that. The
    ec2_metadata
    tree has other facts which are useful and not huge, so I don't want to block the whole thing.
  • s

    Slackbot

    02/25/2023, 6:06 PM
    This message was deleted.
    h
    c
    • 3
    • 16
  • c

    cruelsmith

    02/25/2023, 6:09 PM
    Hi, have a question about how ruby functions default values work. The ruby 4.x API function
    postgresql::postgresql_password
    defines two
    required_param
    and three
    optional_param
    with also default values. That keeped me thinking i can do that in
    .pp
    to skip set the third parameter to be set and only set the fourth one.
    Copy code
    postgresql::postgresql_password('user', 'password', undef, 'md5')
    But that result in spec errors that the third parameter does not match the type and also default value is ignored for that parameter. The parameter type could be changed to
    Optional[...]
    but still the default value gets not applied.
  • c

    cruelsmith

    02/25/2023, 6:11 PM
    Hi, have a question about how ruby functions default values work. The ruby 4.x API function
    postgresql::postgresql_password
    defines two
    required_param
    and three
    optional_param
    with also default values. That keeped me thinking i can do that in
    .pp
    to skip set the third parameter to be set and only set the fourth one.
    Copy code
    postgresql::postgresql_password('user', 'password', undef, 'md5')
    But that result in spec errors that the third parameter does not match the type and also default value is ignored for that parameter. The parameter type could be changed to
    Optional[...]
    but still the default value gets not applied. So it that kind of wanted that the function itself must check for
    Undef
    conversion to
    nil
    ?
  • c

    cruelsmith

    02/25/2023, 6:21 PM
    JFYI: i am talking about that function currently: https://github.com/puppetlabs/puppetlabs-postgresql/blob/main/lib/puppet/functions/postgresql/postgresql_password.rb
  • c

    cruelsmith

    02/25/2023, 6:21 PM
    JFYI: i am talking about that function currently: https://github.com/puppetlabs/puppetlabs-postgresql/blob/main/lib/puppet/functions/postgresql/postgresql_password.rb
  • h

    helindbe

    02/25/2023, 6:23 PM
    4x API does not support named parameters
1...312313314...428Latest