init.sls 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351
  1. #
  2. # Icinga2
  3. #
  4. {% set roles = salt['pillar.get']('nodes:' ~ grains.id ~ ':roles', []) %}
  5. include:
  6. - apt
  7. - sudo
  8. - needrestart
  9. /etc/apt/trusted.gpg.d/icinga.gpg:
  10. file.managed:
  11. - source: salt://icinga2/icinga.gpg
  12. /etc/apt/sources.list.d/icinga.list:
  13. file.managed:
  14. - source: salt://icinga2/icinga.list.tmpl
  15. - template: jinja
  16. - require:
  17. - file: /etc/apt/trusted.gpg.d/icinga.gpg
  18. # Install icinga2 package
  19. icinga2:
  20. pkg.installed:
  21. - name: icinga2
  22. - require:
  23. - file: /etc/apt/sources.list.d/icinga.list
  24. service.running:
  25. - enable: True
  26. - reload: True
  27. # Install plugins (official + our own)
  28. monitoring-plugin-pkgs:
  29. pkg.installed:
  30. - pkgs:
  31. - monitoring-plugins
  32. - nagios-plugins-contrib
  33. - libyaml-syck-perl
  34. - libmonitoring-plugin-perl
  35. - curl
  36. - lsof
  37. - python3-dnspython
  38. - watch_in:
  39. - service: icinga2
  40. ffho-plugins:
  41. file.recurse:
  42. - name: /usr/local/share/monitoring-plugins/
  43. - source: salt://icinga2/plugins/
  44. - file_mode: 755
  45. - dir_mode: 755
  46. - user: root
  47. - group: root
  48. # Install sudoers file for Icinga2 checks
  49. /etc/sudoers.d/icinga2:
  50. file.managed:
  51. - source: salt://icinga2/icinga2.sudoers
  52. - mode: 0440
  53. # Icinga2 master config (for master and all nodes)
  54. /etc/icinga2/icinga2.conf:
  55. file.managed:
  56. - source:
  57. - salt://icinga2/icinga2.conf.H_{{ grains.id }}
  58. - salt://icinga2/icinga2.conf.{{ grains.os }}.{{ grains.oscodename }}
  59. - salt://icinga2/icinga2.conf
  60. - require:
  61. - pkg: icinga2
  62. - watch_in:
  63. - service: icinga2
  64. # Add FFHOPluginDir
  65. /etc/icinga2/constants.conf:
  66. file.managed:
  67. - source: salt://icinga2/constants.conf
  68. - require:
  69. - pkg: icinga2
  70. - watch_in:
  71. - service: icinga2
  72. # Connect "master" and client zones
  73. /etc/icinga2/zones.conf:
  74. file.managed:
  75. - source:
  76. - salt://icinga2/zones.conf.H_{{ grains.id }}
  77. - salt://icinga2/zones.conf
  78. - template: jinja
  79. - require:
  80. - pkg: icinga2
  81. - watch_in:
  82. - service: icinga2
  83. # Install CA cert + host cert + key readable for icinga
  84. /var/lib/icinga2/certs:
  85. file.directory:
  86. - makedirs: True
  87. /var/lib/icinga2/certs/ca.crt:
  88. file.managed:
  89. - source: salt://certs/ffho-cacert.pem
  90. - user: nagios
  91. - group: nagios
  92. - mode: 644
  93. - require:
  94. - pkg: icinga2
  95. - file: /var/lib/icinga2/certs
  96. - watch_in:
  97. - sevice: icinga2
  98. {% set pillar_name = 'nodes:' ~ grains['id'] ~ ':certs:' ~ grains['id'] %}
  99. /var/lib/icinga2/certs/{{ grains['id'] }}.crt:
  100. file.managed:
  101. - contents_pillar: {{ pillar_name }}:cert
  102. - user: nagios
  103. - group: nagios
  104. - mode: 644
  105. - require:
  106. - pkg: icinga2
  107. - file: /var/lib/icinga2/certs
  108. - watch_in:
  109. - service: icinga2
  110. /var/lib/icinga2/certs/{{ grains['id'] }}.key:
  111. file.managed:
  112. - contents_pillar: {{ pillar_name }}:privkey
  113. - user: nagios
  114. - group: nagios
  115. - mode: 440
  116. - require:
  117. - pkg: icinga2
  118. - file: /var/lib/icinga2/certs
  119. - watch_in:
  120. - service: icinga2
  121. # Activate Icinga2 features: API
  122. {% for feature in ['api'] %}
  123. /etc/icinga2/features-enabled/{{ feature }}.conf:
  124. file.symlink:
  125. - target: "../features-available/{{ feature }}.conf"
  126. - user: nagios
  127. - group: nagios
  128. - require:
  129. - pkg: icinga2
  130. - watch_in:
  131. - service: icinga2
  132. {% endfor %}
  133. # Install command definitions
  134. /etc/icinga2/commands.d:
  135. file.recurse:
  136. - source: salt://icinga2/commands.d
  137. - template: jinja
  138. - file_mode: 644
  139. - dir_mode: 755
  140. - user: root
  141. - group: root
  142. - clean: true
  143. - require:
  144. - pkg: icinga2
  145. - watch_in:
  146. - service: icinga2
  147. # Create directory for ffho specific configs
  148. /etc/icinga2/ffho-conf.d:
  149. file.directory:
  150. - makedirs: true
  151. - require:
  152. - pkg: icinga2
  153. ################################################################################
  154. # Icinga2 Server #
  155. ################################################################################
  156. {% if 'icinga2server' in roles %}
  157. # Link ffho-conf.d as master zone
  158. /etc/icinga2/zones.d/master:
  159. file.symlink:
  160. - target: "/etc/icinga2/ffho-conf.d/"
  161. - require:
  162. - pkg: icinga2
  163. - watch_in:
  164. - service: icinga2
  165. # Users and Notifications
  166. /etc/icinga2/ffho-conf.d/users.conf:
  167. file.managed:
  168. - source: salt://icinga2/users.conf.tmpl
  169. - template: jinja
  170. - require:
  171. - pkg: icinga2
  172. - watch_in:
  173. - service: icinga2
  174. /etc/icinga2/ffho-conf.d/notifications.conf:
  175. file.managed:
  176. - source: salt://icinga2/notifications.conf.tmpl
  177. - template: jinja
  178. - require:
  179. - pkg: icinga2
  180. - watch_in:
  181. - service: icinga2
  182. # Install command definitions
  183. /etc/icinga2/ffho-conf.d/services:
  184. file.recurse:
  185. - source: salt://icinga2/services
  186. - file_mode: 644
  187. - dir_mode: 755
  188. - user: root
  189. - group: root
  190. - clean: true
  191. - template: jinja
  192. - require:
  193. - pkg: icinga2
  194. - watch_in:
  195. - service: icinga2
  196. # Create client node/zone objects
  197. Create /etc/icinga2/ffho-conf.d/hosts/generated/:
  198. file.directory:
  199. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  200. - makedirs: true
  201. - require:
  202. - pkg: icinga2
  203. Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/:
  204. file.directory:
  205. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  206. - clean: true
  207. - watch_in:
  208. - service: icinga2
  209. # Generate config file for every client known to pillar
  210. {% for node_id, node_config in salt['pillar.get']('nodes', {}).items () %}
  211. {# Only monitor hosts which are active or staged. #}
  212. {% if node_config.get ('status', '') not in [ '', 'active', 'staged' ] %}
  213. {% continue %}
  214. {% endif %}
  215. /etc/icinga2/ffho-conf.d/hosts/generated/{{ node_id }}.conf:
  216. file.managed:
  217. - source: salt://icinga2/host.conf.tmpl
  218. - template: jinja
  219. - context:
  220. node_id: {{ node_id }}
  221. node_config: {{ node_config }}
  222. - require:
  223. - file: Create /etc/icinga2/ffho-conf.d/hosts/generated/
  224. - require_in:
  225. - file: Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/
  226. - watch_in:
  227. - service: icinga2
  228. {% endfor %}
  229. # Create configuration for network devices
  230. Create /etc/icinga2/ffho-conf.d/net/wbbl/:
  231. file.directory:
  232. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  233. - makedirs: true
  234. - require:
  235. - pkg: icinga2
  236. Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/:
  237. file.directory:
  238. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  239. - makedirs: true
  240. - require:
  241. - pkg: icinga2
  242. - watch_in:
  243. - service: icinga2
  244. # Generate config files for every WBBL device known to pillar
  245. {% for link_id, link_config in salt['pillar.get']('net:wbbl', {}).items () %}
  246. /etc/icinga2/ffho-conf.d/net/wbbl/{{ link_id }}.conf:
  247. file.managed:
  248. - source: salt://icinga2/wbbl.conf.tmpl
  249. - template: jinja
  250. - context:
  251. link_id: {{ link_id }}
  252. link_config: {{ link_config }}
  253. - require:
  254. - file: Create /etc/icinga2/ffho-conf.d/net/wbbl/
  255. - require_in:
  256. - file: Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/
  257. - watch_in:
  258. - service: icinga2
  259. {% endfor %}
  260. ################################################################################
  261. # Icinga2 Client #
  262. ################################################################################
  263. {% else %}
  264. # Nodes should accept config and commands from Icinga2 server
  265. /etc/icinga2/features-available/api.conf:
  266. file.managed:
  267. - source: salt://icinga2/api.conf
  268. - require:
  269. - pkg: icinga2
  270. - watch_in:
  271. - service: icinga2
  272. # Client should not notify by themselves
  273. /etc/icinga2/features-enabled/notification.conf:
  274. file.absent:
  275. - require:
  276. - pkg: icinga2
  277. - watch_in:
  278. - service: icinga2
  279. {% endif %}
  280. ################################################################################
  281. # Check related stuff #
  282. ################################################################################
  283. /etc/icinga2/ffho-conf.d/bird_ospf_interfaces_down_ok.txt:
  284. file.managed:
  285. - source: salt://icinga2/bird_ospf_interfaces_down_ok.txt.tmpl
  286. - template: jinja
  287. - require:
  288. - file: /etc/icinga2/ffho-conf.d
  289. /etc/icinga2/ffho-conf.d/bird_ibgp_sessions_down_ok.txt:
  290. file.managed:
  291. - source: salt://icinga2/bird_ibgp_sessions_down_ok.txt.tmpl
  292. - template: jinja
  293. - require:
  294. - file: /etc/icinga2/ffho-conf.d
  295. salt-cron-state-apply:
  296. cron.present:
  297. - identifier: SALT_CRON_STATE_APPLY
  298. - name: "/usr/bin/salt-call state.highstate --state-verbose=False test=True > /var/cache/salt/state_apply.tmp 2>/dev/null ; mv /var/cache/salt/state_apply.tmp /var/cache/salt/state_apply"
  299. - user: root
  300. - minute: random
  301. - hour: "*/6"