init.sls 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392
  1. #
  2. # Bird routing daemon
  3. #
  4. {%- set roles = salt['pillar.get']('nodes:' ~ grains['id'] ~ ':roles', []) %}
  5. {%- set status = salt['pillar.get']('nodes:' ~ grains['id'] ~ ':status', 'active') %}
  6. include:
  7. - network.interfaces
  8. bird-repo:
  9. file.absent:
  10. - name: /etc/apt/sources.list.d/bird.list
  11. bird-pkg:
  12. pkg.installed:
  13. - name: bird
  14. # Make sure both services are enabled
  15. bird:
  16. service.running:
  17. - enable: True
  18. - running: True
  19. bird6:
  20. service.running:
  21. - enable: True
  22. - running: True
  23. # Reload commands for bird{,6} to be tied to files which should trigger reconfiguration
  24. bird-configure:
  25. cmd.wait:
  26. - name: /usr/sbin/birdc configure
  27. - watch: []
  28. bird6-configure:
  29. cmd.wait:
  30. - name: /usr/sbin/birdc6 configure
  31. - watch: []
  32. /etc/bird:
  33. file.directory:
  34. - mode: 750
  35. - user: bird
  36. - group: bird
  37. - require:
  38. - pkg: bird
  39. /etc/bird/bird.d:
  40. file.directory:
  41. - makedirs: true
  42. - mode: 755
  43. - user: root
  44. - group: bird
  45. - require:
  46. - file: /etc/bird
  47. /etc/bird/bird.conf:
  48. file.managed:
  49. - source: salt://bird/bird.conf
  50. - template: jinja
  51. proto: v4
  52. - require:
  53. - file: /etc/bird/bird.d
  54. - require_in:
  55. - service: bird
  56. - watch_in:
  57. - cmd: bird-configure
  58. - mode: 644
  59. - user: root
  60. - group: bird
  61. /etc/bird/bird6.d:
  62. file.directory:
  63. - makedirs: true
  64. - mode: 755
  65. - user: root
  66. - group: bird
  67. - require:
  68. - file: /etc/bird
  69. /etc/bird/bird6.conf:
  70. file.managed:
  71. - source: salt://bird/bird.conf
  72. - template: jinja
  73. proto: v6
  74. - require:
  75. - file: /etc/bird/bird6.d
  76. - watch_in:
  77. - cmd: bird6-configure
  78. - mode: 644
  79. - user: root
  80. - group: bird
  81. - require_in:
  82. - service: bird6
  83. #
  84. # External VRF / Routing table?
  85. #
  86. /etc/bird/bird.d/VRF_external.conf:
  87. file.managed:
  88. - source: salt://bird/VRF_external.conf
  89. - template: jinja
  90. proto: v4
  91. - watch_in:
  92. - cmd: bird-configure
  93. - require:
  94. - file: /etc/bird/bird.d
  95. - require_in:
  96. - service: bird
  97. /etc/bird/bird6.d/VRF_external.conf:
  98. file.managed:
  99. - source: salt://bird/VRF_external.conf
  100. - template: jinja
  101. proto: v6
  102. - watch_in:
  103. - cmd: bird6-configure
  104. - require:
  105. - file: /etc/bird/bird6.d
  106. - require_in:
  107. - service: bird6
  108. /etc/bird/bird.d/external.conf:
  109. file.absent
  110. /etc/bird/bird6.d/external.conf:
  111. file.absent
  112. #
  113. # IGP / OSPF
  114. #
  115. /etc/bird/bird.d/IGP.conf:
  116. file.managed:
  117. - source: salt://bird/IGP.conf
  118. - template: jinja
  119. proto: v4
  120. - watch_in:
  121. - cmd: bird-configure
  122. - require:
  123. - file: /etc/bird/bird.d
  124. - require_in:
  125. - service: bird
  126. /etc/bird/bird6.d/IGP.conf:
  127. file.managed:
  128. - source: salt://bird/IGP.conf
  129. - template: jinja
  130. proto: v6
  131. - watch_in:
  132. - cmd: bird6-configure
  133. - require:
  134. - file: /etc/bird/bird6.d
  135. - require_in:
  136. - service: bird6
  137. # Compatibility glue
  138. /etc/bird/bird6.d/IGP6.conf:
  139. file.absent:
  140. - watch_in:
  141. - cmd: bird-configure
  142. #
  143. # iBGP
  144. #
  145. /etc/bird/ff-policy.conf:
  146. file.managed:
  147. - source: salt://bird/ff-policy.conf
  148. - template: jinja
  149. proto: v4
  150. - watch_in:
  151. - cmd: bird-configure
  152. - require:
  153. - file: /etc/bird/bird.d
  154. - require_in:
  155. - service: bird
  156. /etc/bird/ff-policy6.conf:
  157. file.managed:
  158. - source: salt://bird/ff-policy.conf
  159. - template: jinja
  160. proto: v6
  161. - watch_in:
  162. - cmd: bird6-configure
  163. - require:
  164. - file: /etc/bird/bird6.d
  165. - require_in:
  166. - service: bird6
  167. /etc/bird/bird.d/ibgp.conf:
  168. file.managed:
  169. - source: salt://bird/ibgp.conf
  170. - template: jinja
  171. proto: v4
  172. - watch_in:
  173. - cmd: bird-configure
  174. - require:
  175. - file: /etc/bird/bird.d
  176. - require_in:
  177. - service: bird
  178. /etc/bird/bird6.d/ibgp.conf:
  179. file.managed:
  180. - source: salt://bird/ibgp.conf
  181. - template: jinja
  182. proto: v6
  183. - watch_in:
  184. - cmd: bird6-configure
  185. - require:
  186. - file: /etc/bird/bird6.d
  187. - require_in:
  188. - service: bird6
  189. #
  190. # FFRL-exit
  191. #
  192. {% if 'ffrl-exit' in roles %}
  193. /etc/bird/bird.d/ffrl.conf:
  194. file.managed:
  195. - source: salt://bird/ffrl.conf
  196. - template: jinja
  197. proto: v4
  198. - watch_in:
  199. - cmd: bird-configure
  200. - require:
  201. - file: /etc/bird/bird.d
  202. - require_in:
  203. - service: bird
  204. /etc/bird/bird6.d/ffrl.conf:
  205. file.managed:
  206. - source: salt://bird/ffrl.conf
  207. - template: jinja
  208. proto: v6
  209. - watch_in:
  210. - cmd: bird6-configure
  211. - require:
  212. - file: /etc/bird/bird6.d
  213. - require_in:
  214. - service: bird6
  215. /etc/bird/bird.d/bogon_unreach.conf:
  216. file.managed:
  217. - source: salt://bird/bogon_unreach.conf
  218. - template: jinja
  219. proto: v4
  220. - watch_in:
  221. - cmd: bird-configure
  222. - require:
  223. - file: /etc/bird/bird.d
  224. - require_in:
  225. - service: bird
  226. /etc/bird/bird6.d/bogon_unreach.conf:
  227. file.managed:
  228. - source: salt://bird/bogon_unreach.conf
  229. - template: jinja
  230. proto: v6
  231. - watch_in:
  232. - cmd: bird6-configure
  233. - require:
  234. - file: /etc/bird/bird6.d
  235. - require_in:
  236. - service: bird6
  237. {% else %}
  238. /etc/bird/bird.d/ffrl.conf:
  239. file.absent:
  240. - watch_in:
  241. - cmd: bird-configure
  242. /etc/bird/bird6.d/ffrl.conf:
  243. file.absent:
  244. - watch_in:
  245. - cmd: bird6-configure
  246. /etc/bird/bird.d/bogon_unreach.conf:
  247. file.absent:
  248. - watch_in:
  249. - cmd: bird-configure
  250. /etc/bird/bird6.d/bogon_unreach.conf:
  251. file.absent:
  252. - watch_in:
  253. - cmd: bird6-configure
  254. {% endif %}
  255. #
  256. # B.A.T.M.A.N. Gateway
  257. #
  258. {% if 'batman_gw' in roles %}
  259. /etc/bird/bird.d/mesh_routes.conf:
  260. file.managed:
  261. - source: salt://bird/mesh_routes.conf
  262. - template: jinja
  263. - watch_in:
  264. - cmd: bird-configure
  265. - require:
  266. - file: /etc/bird/bird.d
  267. - require_in:
  268. - service: bird
  269. /etc/bird/bird6.d/mesh_routes.conf:
  270. file.managed:
  271. - source: salt://bird/mesh_routes.conf
  272. - template: jinja
  273. - watch_in:
  274. - cmd: bird6-configure
  275. - require:
  276. - file: /etc/bird/bird6.d
  277. - require_in:
  278. - service: bird6
  279. {% else %}
  280. /etc/bird/bird.d/mesh_routes.conf:
  281. file.absent:
  282. - watch_in:
  283. - cmd: bird-configure
  284. /etc/bird/bird6.d/mesh_routes.conf:
  285. file.absent:
  286. - watch_in:
  287. - cmd: bird6-configure
  288. {% endif %}
  289. #
  290. # L3 Access
  291. #
  292. {% if 'l3-access' in roles %}
  293. /etc/bird/bird.d/l3-access.conf:
  294. file.managed:
  295. - source: salt://bird/l3-access.conf
  296. - template: jinja
  297. - watch_in:
  298. - cmd: bird-configure
  299. - require:
  300. - file: /etc/bird/bird.d
  301. - require_in:
  302. - service: bird
  303. /etc/bird/bird6.d/l3-access.conf:
  304. file.managed:
  305. - source: salt://bird/l3-access.conf
  306. - template: jinja
  307. - watch_in:
  308. - cmd: bird6-configure
  309. - require:
  310. - file: /etc/bird/bird6.d
  311. - require_in:
  312. - service: bird6
  313. {% else %}
  314. /etc/bird/bird.d/l3-access.conf:
  315. file.absent:
  316. - watch_in:
  317. - cmd: bird-configure
  318. /etc/bird/bird6.d/l3-access.conf:
  319. file.absent:
  320. - watch_in:
  321. - cmd: bird6-configure
  322. {% endif %}
  323. #
  324. # RAdvd (for B.A.T.M.A.N. Gateways / L3-Access)
  325. #
  326. {% if status == 'active' and ('radv' in roles or 'l3-access' in roles or ('batman_gw' in roles and grains.id.startswith('gw'))) %}
  327. /etc/bird/bird6.d/radv.conf:
  328. file.managed:
  329. - source: salt://bird/radv.conf
  330. - template: jinja
  331. - watch_in:
  332. - cmd: bird6-configure
  333. - require:
  334. - file: /etc/bird/bird6.d
  335. - require_in:
  336. - service: bird6
  337. {% else %}
  338. /etc/bird/bird6.d/radv.conf:
  339. file.absent:
  340. - watch_in:
  341. - cmd: bird6-configure
  342. {% endif %}