init.sls 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. #
  2. # Icinga2
  3. #
  4. {% set roles = salt['pillar.get']('nodes:' ~ grains.id ~ ':roles', []) %}
  5. include:
  6. - apt
  7. - sudo
  8. - needrestart
  9. /etc/apt/trusted.gpg.d/icinga.gpg:
  10. file.managed:
  11. - source: salt://icinga2/icinga.gpg
  12. /etc/apt/sources.list.d/icinga.list:
  13. file.managed:
  14. - source: salt://icinga2/icinga.list.tmpl
  15. - template: jinja
  16. - require:
  17. - file: /etc/apt/trusted.gpg.d/icinga.gpg
  18. # Install icinga2 package
  19. icinga2:
  20. pkg.installed:
  21. - name: icinga2
  22. - require:
  23. - file: /etc/apt/sources.list.d/icinga.list
  24. service.running:
  25. - enable: True
  26. - reload: True
  27. # Install plugins (official + our own)
  28. monitoring-plugin-pkgs:
  29. pkg.installed:
  30. - pkgs:
  31. - monitoring-plugins
  32. - nagios-plugins-contrib
  33. - libyaml-syck-perl
  34. - libmonitoring-plugin-perl
  35. - curl
  36. - lsof
  37. - python3-dnspython
  38. - watch_in:
  39. - service: icinga2
  40. ffho-plugins:
  41. file.recurse:
  42. - name: /usr/local/share/monitoring-plugins/
  43. - source: salt://icinga2/plugins/
  44. - file_mode: 755
  45. - dir_mode: 755
  46. - user: root
  47. - group: root
  48. # Install sudoers file for Icinga2 checks
  49. /etc/sudoers.d/icinga2:
  50. file.managed:
  51. - source: salt://icinga2/icinga2.sudoers
  52. - mode: 0440
  53. # Icinga2 master config (for master and all nodes)
  54. /etc/icinga2/icinga2.conf:
  55. file.managed:
  56. - source:
  57. - salt://icinga2/icinga2.conf.H_{{ grains.id }}
  58. - salt://icinga2/icinga2.conf.{{ grains.os }}.{{ grains.oscodename }}
  59. - salt://icinga2/icinga2.conf
  60. - require:
  61. - pkg: icinga2
  62. - watch_in:
  63. - service: icinga2
  64. # Add FFHOPluginDir
  65. /etc/icinga2/constants.conf:
  66. file.managed:
  67. - source: salt://icinga2/constants.conf
  68. - require:
  69. - pkg: icinga2
  70. - watch_in:
  71. - service: icinga2
  72. # Connect "master" and client zones
  73. /etc/icinga2/zones.conf:
  74. file.managed:
  75. - source:
  76. - salt://icinga2/zones.conf.H_{{ grains.id }}
  77. - salt://icinga2/zones.conf
  78. - template: jinja
  79. - require:
  80. - pkg: icinga2
  81. - watch_in:
  82. - service: icinga2
  83. # Install host cert + key readable for icinga
  84. {% set pillar_name = 'nodes:' ~ grains['id'] ~ ':certs:' ~ grains['id'] %}
  85. /etc/icinga2/pki/ffhohost.cert.pem:
  86. file.managed:
  87. {% if salt['pillar.get'](pillar_name ~ ':cert') == "file" %}
  88. - source: salt://certs/certs/{{ cn }}.cert.pem
  89. {% else %}
  90. - contents_pillar: {{ pillar_name }}:cert
  91. {% endif %}
  92. - user: root
  93. - group: root
  94. - mode: 644
  95. - require:
  96. - pkg: icinga2
  97. - watch_in:
  98. - service: icinga2
  99. /etc/icinga2/pki/ffhohost.key.pem:
  100. file.managed:
  101. - contents_pillar: {{ pillar_name }}:privkey
  102. - user: root
  103. - group: nagios
  104. - mode: 440
  105. - require:
  106. - pkg: icinga2
  107. - watch_in:
  108. - service: icinga2
  109. # Activate Icinga2 features: API
  110. {% for feature in ['api'] %}
  111. /etc/icinga2/features-enabled/{{ feature }}.conf:
  112. file.symlink:
  113. - target: "../features-available/{{ feature }}.conf"
  114. - require:
  115. - pkg: icinga2
  116. - watch_in:
  117. - service: icinga2
  118. {% endfor %}
  119. # Install command definitions
  120. /etc/icinga2/commands.d:
  121. file.recurse:
  122. - source: salt://icinga2/commands.d
  123. - template: jinja
  124. - file_mode: 644
  125. - dir_mode: 755
  126. - user: root
  127. - group: root
  128. - clean: true
  129. - require:
  130. - pkg: icinga2
  131. - watch_in:
  132. - service: icinga2
  133. # Create directory for ffho specific configs
  134. /etc/icinga2/ffho-conf.d:
  135. file.directory:
  136. - makedirs: true
  137. - require:
  138. - pkg: icinga2
  139. ################################################################################
  140. # Icinga2 Server #
  141. ################################################################################
  142. {% if 'icinga2server' in roles %}
  143. # Users and Notifications
  144. /etc/icinga2/ffho-conf.d/users.conf:
  145. file.managed:
  146. - source: salt://icinga2/users.conf.tmpl
  147. - template: jinja
  148. - require:
  149. - pkg: icinga2
  150. - watch_in:
  151. - service: icinga2
  152. /etc/icinga2/ffho-conf.d/notifications.conf:
  153. file.managed:
  154. - source: salt://icinga2/notifications.conf.tmpl
  155. - template: jinja
  156. - require:
  157. - pkg: icinga2
  158. - watch_in:
  159. - service: icinga2
  160. # Install command definitions
  161. /etc/icinga2/ffho-conf.d/services:
  162. file.recurse:
  163. - source: salt://icinga2/services
  164. - file_mode: 644
  165. - dir_mode: 755
  166. - user: root
  167. - group: root
  168. - clean: true
  169. - template: jinja
  170. - require:
  171. - pkg: icinga2
  172. - watch_in:
  173. - service: icinga2
  174. # Create client node/zone objects
  175. Create /etc/icinga2/ffho-conf.d/hosts/generated/:
  176. file.directory:
  177. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  178. - makedirs: true
  179. - require:
  180. - pkg: icinga2
  181. Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/:
  182. file.directory:
  183. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  184. - clean: true
  185. - watch_in:
  186. - service: icinga2
  187. # Generate config file for every client known to pillar
  188. {% for node_id, node_config in salt['pillar.get']('nodes', {}).items () %}
  189. {# Only monitor hosts which are active or staged. #}
  190. {% if node_config.get ('status', '') not in [ '', 'active', 'staged' ] %}
  191. {% continue %}
  192. {% endif %}
  193. /etc/icinga2/ffho-conf.d/hosts/generated/{{ node_id }}.conf:
  194. file.managed:
  195. - source: salt://icinga2/host.conf.tmpl
  196. - template: jinja
  197. - context:
  198. node_id: {{ node_id }}
  199. node_config: {{ node_config }}
  200. - require:
  201. - file: Create /etc/icinga2/ffho-conf.d/hosts/generated/
  202. - require_in:
  203. - file: Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/
  204. - watch_in:
  205. - service: icinga2
  206. {% endfor %}
  207. # Create configuration for network devices
  208. Create /etc/icinga2/ffho-conf.d/net/wbbl/:
  209. file.directory:
  210. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  211. - makedirs: true
  212. - require:
  213. - pkg: icinga2
  214. Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/:
  215. file.directory:
  216. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  217. - makedirs: true
  218. - require:
  219. - pkg: icinga2
  220. - watch_in:
  221. - service: icinga2
  222. # Generate config files for every WBBL device known to pillar
  223. {% for link_id, link_config in salt['pillar.get']('net:wbbl', {}).items () %}
  224. /etc/icinga2/ffho-conf.d/net/wbbl/{{ link_id }}.conf:
  225. file.managed:
  226. - source: salt://icinga2/wbbl.conf.tmpl
  227. - template: jinja
  228. - context:
  229. link_id: {{ link_id }}
  230. link_config: {{ link_config }}
  231. - require:
  232. - file: Create /etc/icinga2/ffho-conf.d/net/wbbl/
  233. - require_in:
  234. - file: Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/
  235. - watch_in:
  236. - service: icinga2
  237. {% endfor %}
  238. ################################################################################
  239. # Icinga2 Client #
  240. ################################################################################
  241. {% else %}
  242. # Nodes should accept config and commands from Icinga2 server
  243. /etc/icinga2/features-available/api.conf:
  244. file.managed:
  245. - source: salt://icinga2/api.conf
  246. - require:
  247. - pkg: icinga2
  248. - watch_in:
  249. - service: icinga2
  250. # Client should not notify by themselves
  251. /etc/icinga2/features-enabled/notification.conf:
  252. file.absent:
  253. - watch_in:
  254. - service: icinga2
  255. {% endif %}
  256. ################################################################################
  257. # Check related stuff #
  258. ################################################################################
  259. /etc/icinga2/ffho-conf.d/bird_ospf_interfaces_down_ok.txt:
  260. file.managed:
  261. - source: salt://icinga2/bird_ospf_interfaces_down_ok.txt.tmpl
  262. - template: jinja
  263. - require:
  264. - file: /etc/icinga2/ffho-conf.d
  265. /etc/icinga2/ffho-conf.d/bird_ibgp_sessions_down_ok.txt:
  266. file.managed:
  267. - source: salt://icinga2/bird_ibgp_sessions_down_ok.txt.tmpl
  268. - template: jinja
  269. - require:
  270. - file: /etc/icinga2/ffho-conf.d
  271. salt-cron-state-apply:
  272. cron.present:
  273. - identifier: SALT_CRON_STATE_APPLY
  274. - name: "/usr/bin/salt-call state.highstate --state-verbose=False test=True > /var/cache/salt/state_apply.tmp 2>/dev/null ; mv /var/cache/salt/state_apply.tmp /var/cache/salt/state_apply"
  275. - user: root
  276. - minute: random
  277. - hour: "*/6"