init.sls 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. #
  2. # Icinga2
  3. #
  4. {% set roles = salt['pillar.get']('nodes:' ~ grains.id ~ ':roles', []) %}
  5. include:
  6. - apt
  7. # Install icinga2 package
  8. icinga2:
  9. pkg.installed:
  10. - name: icinga2
  11. service.running:
  12. - enable: True
  13. - reload: True
  14. # Install plugins (official + our own)
  15. monitoring-plugin-pkgs:
  16. pkg.installed:
  17. - pkgs:
  18. - monitoring-plugins
  19. - nagios-plugins-contrib
  20. - libyaml-syck-perl
  21. {% if grains['oscodename'] == 'jessie' %}
  22. - libnagios-plugin-perl
  23. {% else %}
  24. - libmonitoring-plugin-perl
  25. {% endif %}
  26. - lsof
  27. - watch_in:
  28. - service: icinga2
  29. ffho-plugins:
  30. file.recurse:
  31. - name: /usr/local/share/monitoring-plugins/
  32. - source: salt://icinga2/plugins/
  33. - file_mode: 755
  34. - dir_mode: 755
  35. - user: root
  36. - group: root
  37. # Install sudo
  38. sudo:
  39. pkg.installed
  40. /etc/sudoers.d/icinga2:
  41. file.managed:
  42. - source: salt://icinga2/icinga2.sudoers
  43. - mode: 0440
  44. # Icinga2 master config (for master and all nodes)
  45. /etc/icinga2/icinga2.conf:
  46. file.managed:
  47. - source:
  48. - salt://icinga2/icinga2.conf.H_{{ grains.id }}
  49. - salt://icinga2/icinga2.conf
  50. - require:
  51. - pkg: icinga2
  52. - watch_in:
  53. - service: icinga2
  54. # Add FFHOPluginDir
  55. /etc/icinga2/constants.conf:
  56. file.managed:
  57. - source: salt://icinga2/constants.conf
  58. - require:
  59. - pkg: icinga2
  60. - watch_in:
  61. - service: icinga2
  62. # Connect "master" and client zones
  63. /etc/icinga2/zones.conf:
  64. file.managed:
  65. - source:
  66. - salt://icinga2/zones.conf.H_{{ grains.id }}
  67. - salt://icinga2/zones.conf
  68. - require:
  69. - pkg: icinga2
  70. - watch_in:
  71. - service: icinga2
  72. # Install host cert + key readable for icinga
  73. {% set pillar_name = 'nodes:' ~ grains['id'] ~ ':certs:' ~ grains['id'] %}
  74. /etc/icinga2/pki/ffhohost.cert.pem:
  75. file.managed:
  76. {% if salt['pillar.get'](pillar_name ~ ':cert') == "file" %}
  77. - source: salt://certs/certs/{{ cn }}.cert.pem
  78. {% else %}
  79. - contents_pillar: {{ pillar_name }}:cert
  80. {% endif %}
  81. - user: root
  82. - group: root
  83. - mode: 644
  84. - require:
  85. - pkg: icinga2
  86. - watch_in:
  87. - service: icinga2
  88. /etc/icinga2/pki/ffhohost.key.pem:
  89. file.managed:
  90. - contents_pillar: {{ pillar_name }}:privkey
  91. - user: root
  92. - group: nagios
  93. - mode: 440
  94. - require:
  95. - pkg: icinga2
  96. - watch_in:
  97. - service: icinga2
  98. # Activate Icinga2 features: API
  99. {% for feature in ['api'] %}
  100. /etc/icinga2/features-enabled/{{ feature }}.conf:
  101. file.symlink:
  102. - target: "../features-available/{{ feature }}.conf"
  103. - require:
  104. - pkg: icinga2
  105. - watch_in:
  106. - service: icinga2
  107. {% endfor %}
  108. # Install command definitions
  109. /etc/icinga2/commands.d:
  110. file.recurse:
  111. - source: salt://icinga2/commands.d
  112. - file_mode: 644
  113. - dir_mode: 755
  114. - user: root
  115. - group: root
  116. - clean: true
  117. - require:
  118. - pkg: icinga2
  119. - watch_in:
  120. - service: icinga2
  121. # Create directory for ffho specific configs
  122. /etc/icinga2/ffho-conf.d:
  123. file.directory:
  124. - makedirs: true
  125. - require:
  126. - pkg: icinga2
  127. ################################################################################
  128. # Icinga2 Server #
  129. ################################################################################
  130. {% if 'icinga2server' in roles %}
  131. # Install command definitions
  132. /etc/icinga2/ffho-conf.d/services:
  133. file.recurse:
  134. - source: salt://icinga2/services
  135. - file_mode: 644
  136. - dir_mode: 755
  137. - user: root
  138. - group: root
  139. - clean: true
  140. - require:
  141. - pkg: icinga2
  142. - watch_in:
  143. - service: icinga2
  144. # Create client node/zone objects
  145. Create /etc/icinga2/ffho-conf.d/hosts/generated/:
  146. file.directory:
  147. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  148. - makedirs: true
  149. - require:
  150. - pkg: icinga2
  151. Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/:
  152. file.directory:
  153. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  154. - clean: true
  155. - watch_in:
  156. - service: icinga2
  157. # Generate config file for every client known to pillar
  158. {% for node_id, node_config in salt['pillar.get']('nodes', {}).items () %}
  159. {% if node_config.get ('icinga2', "") != 'ignore' %}
  160. /etc/icinga2/ffho-conf.d/hosts/generated/{{ node_id }}.conf:
  161. file.managed:
  162. - source: salt://icinga2/host.conf.tmpl
  163. - template: jinja
  164. - context:
  165. node_id: {{ node_id }}
  166. node_config: {{ node_config }}
  167. - require:
  168. - file: Create /etc/icinga2/ffho-conf.d/hosts/generated/
  169. - require_in:
  170. - file: Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/
  171. - watch_in:
  172. - service: icinga2
  173. {% endif %}
  174. {% endfor %}
  175. # Create configuration for network devices
  176. Create /etc/icinga2/ffho-conf.d/net/wbbl/:
  177. file.directory:
  178. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  179. - makedirs: true
  180. - require:
  181. - pkg: icinga2
  182. Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/:
  183. file.directory:
  184. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  185. - makedirs: true
  186. - require:
  187. - pkg: icinga2
  188. - watch_in:
  189. - service: icinga2
  190. # Generate config files for every WBBL device known to pillar
  191. {% for link_id, link_config in salt['pillar.get']('net:wbbl', {}).items () %}
  192. /etc/icinga2/ffho-conf.d/net/wbbl/{{ link_id }}.conf:
  193. file.managed:
  194. - source: salt://icinga2/wbbl.conf.tmpl
  195. - template: jinja
  196. - context:
  197. link_id: {{ link_id }}
  198. link_config: {{ link_config }}
  199. - require:
  200. - file: Create /etc/icinga2/ffho-conf.d/net/wbbl/
  201. - require_in:
  202. - file: Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/
  203. - watch_in:
  204. - service: icinga2
  205. {% endfor %}
  206. ################################################################################
  207. # Icinga2 Client #
  208. ################################################################################
  209. {% else %}
  210. # Nodes should accept config and commands from Icinga2 server
  211. /etc/icinga2/features-available/api.conf:
  212. file.managed:
  213. - source: salt://icinga2/api.conf
  214. - require:
  215. - pkg: icinga2
  216. - watch_in:
  217. - service: icinga2
  218. /etc/icinga2/check-commands.conf:
  219. file.absent:
  220. - watch_in:
  221. - service: icinga2
  222. {% endif %}
  223. ################################################################################
  224. # Check related stuff #
  225. ################################################################################
  226. /etc/icinga2/ffho-conf.d/bird_ospf_interfaces_down_ok.txt:
  227. file.managed:
  228. - source: salt://icinga2/bird_ospf_interfaces_down_ok.txt.tmpl
  229. - template: jinja
  230. - require:
  231. - file: /etc/icinga2/ffho-conf.d