Slackbot
02/27/2023, 8:27 PMnatemccurdy
02/27/2023, 8:50 PMnatemccurdy
02/27/2023, 9:05 PMdns_alt_names to the [server] section of puppet.conf before starting puppetserver for the first time.
That can be done manually:
sudo mkdir -p /etc/puppetlabs/puppet
sudo vim /etc/puppetlabs/puppet/puppet.conf
Or with:
sudo puppet config set dns_alt_names --section server name1,name2,name3Slackbot
02/27/2023, 10:25 PMSlackbot
02/28/2023, 1:30 AMWilliam Myers
02/28/2023, 1:31 AMnatemccurdy
02/28/2023, 1:46 AMapp that identifies that application that is running on a node, you could do something like the above example that just has a static list of app names to "onboard" to the new feature.natemccurdy
02/28/2023, 1:46 AMclass windows_mitigations (
Boolean $enable_new_mitigations = false,
) {
if $enable_new_mititgations {
registry_value { 'foo/bar':
ensure => present,
data => 'hello',
}
}
1. The feature flag is false by default. This means you can push the change out and nothing will happen. It lets you stage the feature without enabling it.
2. Where you would declare the class that controls windows mitigations, you flip that feature flag parameter to true when you want to rollout to a new app.William Myers
02/28/2023, 1:48 AMnatemccurdy
02/28/2023, 1:49 AMnatemccurdy
02/28/2023, 1:50 AMnatemccurdy
02/28/2023, 1:51 AMThe goal is basically to limit the deployment to a portion of the environment, and not let er rip against the entirety of "production" including currently uncategorized db serversYeah, definitely. And this is made easier with custom facts. If there's a custom fact that portions your nodes in some way, you could use that fact to limit the blast radius of a change via the feature flag model.
natemccurdy
02/28/2023, 1:51 AMThe goal is basically to limit the deployment to a portion of the environment, and not let er rip against the entirety of "production" including currently uncategorized db serversYeah, definitely. And this is made easier with custom facts or ENC data. If there's a custom fact that portions your nodes in some way, you could use that fact to limit the blast radius of a change via the feature flag model.
natemccurdy
02/28/2023, 1:52 AMnatemccurdy
02/28/2023, 1:52 AMnatemccurdy
02/28/2023, 2:00 AMnatemccurdy
02/28/2023, 2:02 AMnode definitions per node that set some variable. Or have a giant if or case statement in site.pp that sets that variable.
Now.... that's a terrible idea... and is why it's good to have facts or ENC data so that you can group your nodes.William Myers
02/28/2023, 2:04 AMnode default {
include profile::base
}
### Debian (x86_64)
node 'vmipam01.britanniahome.local' {
include profile::base
include profile::phpipam::phpipam_apache
}
node '<http://vmsftp.britanniahome.net|vmsftp.britanniahome.net>' {
include profile::base
include profile::sftp::vmsftp::vmsftp_config
include accounts
include fail2ban
}
## Windows
## debian (arm64)
node '<http://octopi.britanniahome.net|octopi.britanniahome.net>' {
include profile::base::linux_directories # site wide direcories
include serviceaccounts::linux::root # linux root user account
}
### Template VMs:
node '<http://tmplt-ubntu-2004.britanniahome.net|tmplt-ubntu-2004.britanniahome.net>' {
include profile::vmtemplate
}natemccurdy
02/28/2023, 2:07 AMWilliam Myers
02/28/2023, 2:08 AMnatemccurdy
02/28/2023, 2:11 AMWilliam Myers
02/28/2023, 2:14 AMYury Bushmelev
02/28/2023, 2:17 AMWilliam Myers
02/28/2023, 2:51 AMWilliam Myers
02/28/2023, 3:59 AMWilliam Myers
02/28/2023, 5:45 AMWilliam Myers
02/28/2023, 6:12 AMWilliam Myers
02/28/2023, 6:52 AMssh::server_options:
protocol: '2'
Port: '22'
PasswordAuthentication: 'no'
PermitRootLogin: 'no'
ChallengeResponseAuthentication: 'no'
# ChrootDirectory: '%h'
UsePAM: 'yes'
AllowTcpForwarding: 'no'
X11Forwarding: 'no'
LoginGraceTime: '1m'
MaxAuthTries: '4'
MaxSessions: '20'
MaxStartups: '10:30:100'
KexAlgorithms: '-diffie-hellman-group1-sha1,diffie-hellman-group-exchange-sha1,ecdh-sha2-nistp256'
ciphers: '-aes128-cbc,aes256-cbc'
PrintMotd: 'no'
Subsystem: 'sftp internal-sftp'
Match group sftponly:
ForceCommand: 'internal-sftp -u 027'
ChrootDirectory: '/srv/sftpdata/%u'
PermitTunnel: 'no'
AllowAgentForwarding: 'no'
AllowTcpForwarding: 'no'
X11Forwarding: 'no'
PasswordAuthentication: 'yes'
Match all:William Myers
02/28/2023, 6:53 AMssh::server_options:
protocol: '2'
Port: '22'
PasswordAuthentication: 'no'
PermitRootLogin: 'no'
ChallengeResponseAuthentication: 'no'
# ChrootDirectory: '%h'
UsePAM: 'yes'
AllowTcpForwarding: 'no'
X11Forwarding: 'no'
LoginGraceTime: '1m'
MaxAuthTries: '4'
MaxSessions: '20'
MaxStartups: '10:30:100'
KexAlgorithms: '-diffie-hellman-group1-sha1,diffie-hellman-group-exchange-sha1,ecdh-sha2-nistp256'
ciphers: '-aes128-cbc,aes256-cbc'
PrintMotd: 'no'
Subsystem: 'sftp internal-sftp'
Match group sftponly:
ForceCommand: 'internal-sftp -u 027'
ChrootDirectory: '/srv/sftpdata/%u'
PermitTunnel: 'no'
AllowAgentForwarding: 'no'
AllowTcpForwarding: 'no'
X11Forwarding: 'no'
PasswordAuthentication: 'yes'
Match all:Slackbot
02/28/2023, 7:18 AM