init.sls 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335
  1. #
  2. # Icinga2
  3. #
  4. {% set roles = salt['pillar.get']('nodes:' ~ grains.id ~ ':roles', []) %}
  5. include:
  6. - apt
  7. - sudo
  8. - needrestart
  9. /etc/apt/trusted.gpg.d/icinga.gpg:
  10. file.managed:
  11. - source: salt://icinga2/icinga.gpg
  12. /etc/apt/sources.list.d/icinga.list:
  13. file.managed:
  14. - source: salt://icinga2/icinga.list.tmpl
  15. - template: jinja
  16. - require:
  17. - file: /etc/apt/trusted.gpg.d/icinga.gpg
  18. # Install icinga2 package
  19. icinga2:
  20. pkg.installed:
  21. - name: icinga2
  22. - require:
  23. - file: /etc/apt/sources.list.d/icinga.list
  24. service.running:
  25. - enable: True
  26. - reload: True
  27. /etc/systemd/system/icinga2.service.d/override.conf:
  28. file.absent
  29. systemd-reload:
  30. cmd.run:
  31. - name: systemctl daemon-reload
  32. - watch:
  33. - file: /etc/systemd/system/icinga2.service.d/override.conf
  34. - watch_in:
  35. - service: icinga2
  36. # Install plugins (official + our own)
  37. monitoring-plugin-pkgs:
  38. pkg.installed:
  39. - pkgs:
  40. - monitoring-plugins
  41. - nagios-plugins-contrib
  42. - libyaml-syck-perl
  43. - libmonitoring-plugin-perl
  44. - curl
  45. - lsof
  46. - python3-dnspython
  47. - watch_in:
  48. - service: icinga2
  49. ffho-plugins:
  50. file.recurse:
  51. - name: /usr/local/share/monitoring-plugins/
  52. - source: salt://icinga2/plugins/
  53. - file_mode: 755
  54. - dir_mode: 755
  55. - user: root
  56. - group: root
  57. # Install sudoers file for Icinga2 checks
  58. /etc/sudoers.d/icinga2:
  59. file.managed:
  60. - source: salt://icinga2/icinga2.sudoers
  61. - mode: 0440
  62. # Icinga2 master config (for master and all nodes)
  63. /etc/icinga2/icinga2.conf:
  64. file.managed:
  65. - source:
  66. - salt://icinga2/icinga2.conf.H_{{ grains.id }}
  67. - salt://icinga2/icinga2.conf.{{ grains.os }}.{{ grains.oscodename }}
  68. - salt://icinga2/icinga2.conf
  69. - require:
  70. - pkg: icinga2
  71. - watch_in:
  72. - service: icinga2
  73. # Add FFHOPluginDir
  74. /etc/icinga2/constants.conf:
  75. file.managed:
  76. - source: salt://icinga2/constants.conf
  77. - require:
  78. - pkg: icinga2
  79. - watch_in:
  80. - service: icinga2
  81. # Connect "master" and client zones
  82. /etc/icinga2/zones.conf:
  83. file.managed:
  84. - source:
  85. - salt://icinga2/zones.conf.H_{{ grains.id }}
  86. - salt://icinga2/zones.conf
  87. - template: jinja
  88. - require:
  89. - pkg: icinga2
  90. - watch_in:
  91. - service: icinga2
  92. # Install host cert + key readable for icinga
  93. {% set pillar_name = 'nodes:' ~ grains['id'] ~ ':certs:' ~ grains['id'] %}
  94. /etc/icinga2/pki/ffhohost.cert.pem:
  95. file.managed:
  96. {% if salt['pillar.get'](pillar_name ~ ':cert') == "file" %}
  97. - source: salt://certs/certs/{{ cn }}.cert.pem
  98. {% else %}
  99. - contents_pillar: {{ pillar_name }}:cert
  100. {% endif %}
  101. - user: root
  102. - group: root
  103. - mode: 644
  104. - require:
  105. - pkg: icinga2
  106. - watch_in:
  107. - service: icinga2
  108. /etc/icinga2/pki/ffhohost.key.pem:
  109. file.managed:
  110. - contents_pillar: {{ pillar_name }}:privkey
  111. - user: root
  112. - group: nagios
  113. - mode: 440
  114. - require:
  115. - pkg: icinga2
  116. - watch_in:
  117. - service: icinga2
  118. # Activate Icinga2 features: API
  119. {% for feature in ['api'] %}
  120. /etc/icinga2/features-enabled/{{ feature }}.conf:
  121. file.symlink:
  122. - target: "../features-available/{{ feature }}.conf"
  123. - require:
  124. - pkg: icinga2
  125. - watch_in:
  126. - service: icinga2
  127. {% endfor %}
  128. # Install command definitions
  129. /etc/icinga2/commands.d:
  130. file.recurse:
  131. - source: salt://icinga2/commands.d
  132. - template: jinja
  133. - file_mode: 644
  134. - dir_mode: 755
  135. - user: root
  136. - group: root
  137. - clean: true
  138. - require:
  139. - pkg: icinga2
  140. - watch_in:
  141. - service: icinga2
  142. # Create directory for ffho specific configs
  143. /etc/icinga2/ffho-conf.d:
  144. file.directory:
  145. - makedirs: true
  146. - require:
  147. - pkg: icinga2
  148. ################################################################################
  149. # Icinga2 Server #
  150. ################################################################################
  151. {% if 'icinga2server' in roles %}
  152. # Users and Notifications
  153. /etc/icinga2/ffho-conf.d/users.conf:
  154. file.managed:
  155. - source: salt://icinga2/users.conf.tmpl
  156. - template: jinja
  157. - require:
  158. - pkg: icinga2
  159. - watch_in:
  160. - service: icinga2
  161. /etc/icinga2/ffho-conf.d/notifications.conf:
  162. file.managed:
  163. - source: salt://icinga2/notifications.conf.tmpl
  164. - template: jinja
  165. - require:
  166. - pkg: icinga2
  167. - watch_in:
  168. - service: icinga2
  169. # Install command definitions
  170. /etc/icinga2/ffho-conf.d/services:
  171. file.recurse:
  172. - source: salt://icinga2/services
  173. - file_mode: 644
  174. - dir_mode: 755
  175. - user: root
  176. - group: root
  177. - clean: true
  178. - template: jinja
  179. - require:
  180. - pkg: icinga2
  181. - watch_in:
  182. - service: icinga2
  183. # Create client node/zone objects
  184. Create /etc/icinga2/ffho-conf.d/hosts/generated/:
  185. file.directory:
  186. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  187. - makedirs: true
  188. - require:
  189. - pkg: icinga2
  190. Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/:
  191. file.directory:
  192. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  193. - clean: true
  194. - watch_in:
  195. - service: icinga2
  196. # Generate config file for every client known to pillar
  197. {% for node_id, node_config in salt['pillar.get']('nodes', {}).items () %}
  198. {# Only monitor hosts which are active or staged. #}
  199. {% if node_config.get ('status', '') not in [ '', 'active', 'staged' ] %}
  200. {% continue %}
  201. {% endif %}
  202. /etc/icinga2/ffho-conf.d/hosts/generated/{{ node_id }}.conf:
  203. file.managed:
  204. - source: salt://icinga2/host.conf.tmpl
  205. - template: jinja
  206. - context:
  207. node_id: {{ node_id }}
  208. node_config: {{ node_config }}
  209. - require:
  210. - file: Create /etc/icinga2/ffho-conf.d/hosts/generated/
  211. - require_in:
  212. - file: Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/
  213. - watch_in:
  214. - service: icinga2
  215. {% endfor %}
  216. # Create configuration for network devices
  217. Create /etc/icinga2/ffho-conf.d/net/wbbl/:
  218. file.directory:
  219. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  220. - makedirs: true
  221. - require:
  222. - pkg: icinga2
  223. Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/:
  224. file.directory:
  225. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  226. - makedirs: true
  227. - require:
  228. - pkg: icinga2
  229. - watch_in:
  230. - service: icinga2
  231. # Generate config files for every WBBL device known to pillar
  232. {% for link_id, link_config in salt['pillar.get']('net:wbbl', {}).items () %}
  233. /etc/icinga2/ffho-conf.d/net/wbbl/{{ link_id }}.conf:
  234. file.managed:
  235. - source: salt://icinga2/wbbl.conf.tmpl
  236. - template: jinja
  237. - context:
  238. link_id: {{ link_id }}
  239. link_config: {{ link_config }}
  240. - require:
  241. - file: Create /etc/icinga2/ffho-conf.d/net/wbbl/
  242. - require_in:
  243. - file: Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/
  244. - watch_in:
  245. - service: icinga2
  246. {% endfor %}
  247. ################################################################################
  248. # Icinga2 Client #
  249. ################################################################################
  250. {% else %}
  251. # Nodes should accept config and commands from Icinga2 server
  252. /etc/icinga2/features-available/api.conf:
  253. file.managed:
  254. - source: salt://icinga2/api.conf
  255. - require:
  256. - pkg: icinga2
  257. - watch_in:
  258. - service: icinga2
  259. # Client should not notify by themselves
  260. /etc/icinga2/features-enabled/notification.conf:
  261. file.absent:
  262. - watch_in:
  263. - service: icinga2
  264. {% endif %}
  265. ################################################################################
  266. # Check related stuff #
  267. ################################################################################
  268. /etc/icinga2/ffho-conf.d/bird_ospf_interfaces_down_ok.txt:
  269. file.managed:
  270. - source: salt://icinga2/bird_ospf_interfaces_down_ok.txt.tmpl
  271. - template: jinja
  272. - require:
  273. - file: /etc/icinga2/ffho-conf.d
  274. /etc/icinga2/ffho-conf.d/bird_ibgp_sessions_down_ok.txt:
  275. file.managed:
  276. - source: salt://icinga2/bird_ibgp_sessions_down_ok.txt.tmpl
  277. - template: jinja
  278. - require:
  279. - file: /etc/icinga2/ffho-conf.d
  280. salt-cron-state-apply:
  281. cron.present:
  282. - identifier: SALT_CRON_STATE_APPLY
  283. - name: "/usr/bin/salt-call state.highstate --state-verbose=False test=True > /var/cache/salt/state_apply.tmp 2>/dev/null ; mv /var/cache/salt/state_apply.tmp /var/cache/salt/state_apply"
  284. - user: root
  285. - minute: random
  286. - hour: "*/6"