init.sls 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348
  1. #
  2. # Icinga2
  3. #
  4. {% set roles = salt['pillar.get']('nodes:' ~ grains.id ~ ':roles', []) %}
  5. include:
  6. - apt
  7. - sudo
  8. - needrestart
  9. /etc/apt/trusted.gpg.d/icinga.gpg:
  10. file.managed:
  11. - source: salt://icinga2/icinga.gpg
  12. /etc/apt/sources.list.d/icinga.list:
  13. file.managed:
  14. - source: salt://icinga2/icinga.list.tmpl
  15. - template: jinja
  16. - require:
  17. - file: /etc/apt/trusted.gpg.d/icinga.gpg
  18. # Install icinga2 package
  19. icinga2:
  20. pkg.installed:
  21. - name: icinga2
  22. - require:
  23. - file: /etc/apt/sources.list.d/icinga.list
  24. service.running:
  25. - enable: True
  26. - reload: True
  27. # Install plugins (official + our own)
  28. monitoring-plugin-pkgs:
  29. pkg.installed:
  30. - pkgs:
  31. - monitoring-plugins
  32. - nagios-plugins-contrib
  33. - libyaml-syck-perl
  34. - libmonitoring-plugin-perl
  35. - curl
  36. - lsof
  37. - python3-dnspython
  38. - python3-tz
  39. - watch_in:
  40. - service: icinga2
  41. ffho-plugins:
  42. file.recurse:
  43. - name: /usr/local/share/monitoring-plugins/
  44. - source: salt://icinga2/plugins/
  45. - file_mode: 755
  46. - dir_mode: 755
  47. - user: root
  48. - group: root
  49. # Install sudoers file for Icinga2 checks
  50. /etc/sudoers.d/icinga2:
  51. file.managed:
  52. - source: salt://icinga2/icinga2.sudoers
  53. - mode: 0440
  54. # Icinga2 master config (for master and all nodes)
  55. /etc/icinga2/icinga2.conf:
  56. file.managed:
  57. - source:
  58. - salt://icinga2/icinga2.conf.H_{{ grains.id }}
  59. - salt://icinga2/icinga2.conf.{{ grains.os }}.{{ grains.oscodename }}
  60. - salt://icinga2/icinga2.conf
  61. - require:
  62. - pkg: icinga2
  63. - watch_in:
  64. - service: icinga2
  65. # Add FFHOPluginDir
  66. /etc/icinga2/constants.conf:
  67. file.managed:
  68. - source: salt://icinga2/constants.conf
  69. - require:
  70. - pkg: icinga2
  71. - watch_in:
  72. - service: icinga2
  73. {% if grains['id'] in ["icinga2.in.ffho.net"] %}
  74. /etc/icinga2/secrets.conf:
  75. file.managed:
  76. - source: salt://icinga2/secrets.conf.tmpl
  77. - template: jinja
  78. - mode: 600
  79. - require:
  80. - pkg: icinga2
  81. - watch_in:
  82. - service: icinga2
  83. {% endif %}
  84. # Connect "master" and client zones
  85. /etc/icinga2/zones.conf:
  86. file.managed:
  87. - source:
  88. - salt://icinga2/zones.conf.H_{{ grains.id }}
  89. - salt://icinga2/zones.conf
  90. - template: jinja
  91. - require:
  92. - pkg: icinga2
  93. - watch_in:
  94. - service: icinga2
  95. # Install CA cert + host cert + key readable for icinga
  96. /var/lib/icinga2/certs:
  97. file.directory:
  98. - makedirs: True
  99. /var/lib/icinga2/certs/ca.crt:
  100. file.managed:
  101. - source: salt://certs/ffho-cacert.pem
  102. - user: nagios
  103. - group: nagios
  104. - mode: 644
  105. - require:
  106. - pkg: icinga2
  107. - file: /var/lib/icinga2/certs
  108. - watch_in:
  109. - sevice: icinga2
  110. {% set pillar_name = 'nodes:' ~ grains['id'] ~ ':certs:' ~ grains['id'] %}
  111. /var/lib/icinga2/certs/{{ grains['id'] }}.crt:
  112. file.managed:
  113. - contents_pillar: {{ pillar_name }}:cert
  114. - user: nagios
  115. - group: nagios
  116. - mode: 644
  117. - require:
  118. - pkg: icinga2
  119. - file: /var/lib/icinga2/certs
  120. - watch_in:
  121. - service: icinga2
  122. /var/lib/icinga2/certs/{{ grains['id'] }}.key:
  123. file.managed:
  124. - contents_pillar: {{ pillar_name }}:privkey
  125. - user: nagios
  126. - group: nagios
  127. - mode: 440
  128. - require:
  129. - pkg: icinga2
  130. - file: /var/lib/icinga2/certs
  131. - watch_in:
  132. - service: icinga2
  133. # Activate Icinga2 features: API
  134. {% for feature in ['api'] %}
  135. /etc/icinga2/features-enabled/{{ feature }}.conf:
  136. file.symlink:
  137. - target: "../features-available/{{ feature }}.conf"
  138. - user: nagios
  139. - group: nagios
  140. - require:
  141. - pkg: icinga2
  142. - watch_in:
  143. - service: icinga2
  144. {% endfor %}
  145. # Install command definitions
  146. /etc/icinga2/commands.d:
  147. file.recurse:
  148. - source: salt://icinga2/commands.d
  149. - template: jinja
  150. - file_mode: 644
  151. - dir_mode: 755
  152. - user: root
  153. - group: root
  154. - clean: true
  155. - require:
  156. - pkg: icinga2
  157. - watch_in:
  158. - service: icinga2
  159. # Create directory for ffho specific configs
  160. /etc/icinga2/ffho-conf.d:
  161. file.directory:
  162. - makedirs: true
  163. - require:
  164. - pkg: icinga2
  165. ################################################################################
  166. # Icinga2 Server #
  167. ################################################################################
  168. {% if 'icinga2server' in roles %}
  169. # Link ffho-conf.d as master zone
  170. /etc/icinga2/zones.d/master:
  171. file.symlink:
  172. - target: "/etc/icinga2/ffho-conf.d/"
  173. - require:
  174. - pkg: icinga2
  175. - watch_in:
  176. - service: icinga2
  177. # Users and Notifications
  178. /etc/icinga2/ffho-conf.d/users.conf:
  179. file.managed:
  180. - source: salt://icinga2/users.conf.tmpl
  181. - template: jinja
  182. - require:
  183. - pkg: icinga2
  184. - watch_in:
  185. - service: icinga2
  186. /etc/icinga2/ffho-conf.d/notifications.conf:
  187. file.managed:
  188. - source: salt://icinga2/notifications.conf.tmpl
  189. - template: jinja
  190. - require:
  191. - pkg: icinga2
  192. - watch_in:
  193. - service: icinga2
  194. # Install command definitions
  195. /etc/icinga2/ffho-conf.d/services:
  196. file.recurse:
  197. - source: salt://icinga2/services
  198. - file_mode: 644
  199. - dir_mode: 755
  200. - user: root
  201. - group: root
  202. - clean: true
  203. - template: jinja
  204. - require:
  205. - pkg: icinga2
  206. - watch_in:
  207. - service: icinga2
  208. # Create client node/zone objects
  209. Create /etc/icinga2/ffho-conf.d/hosts/generated/:
  210. file.directory:
  211. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  212. - makedirs: true
  213. - require:
  214. - pkg: icinga2
  215. Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/:
  216. file.directory:
  217. - name: /etc/icinga2/ffho-conf.d/hosts/generated/
  218. - clean: true
  219. - watch_in:
  220. - service: icinga2
  221. # Generate config file for every client known to pillar
  222. {% for node_id, node_config in salt['pillar.get']('nodes', {}).items () %}
  223. {# Only monitor hosts which are active or staged. #}
  224. {% if node_config.get ('status', '') not in [ '', 'active', 'staged' ] %}
  225. {% continue %}
  226. {% endif %}
  227. /etc/icinga2/ffho-conf.d/hosts/generated/{{ node_id }}.conf:
  228. file.managed:
  229. - source: salt://icinga2/host.conf.tmpl
  230. - template: jinja
  231. - context:
  232. node_id: {{ node_id }}
  233. node_config: {{ node_config }}
  234. - require:
  235. - file: Create /etc/icinga2/ffho-conf.d/hosts/generated/
  236. - require_in:
  237. - file: Cleanup /etc/icinga2/ffho-conf.d/hosts/generated/
  238. - watch_in:
  239. - service: icinga2
  240. {% endfor %}
  241. # Create configuration for network devices
  242. Create /etc/icinga2/ffho-conf.d/net/wbbl/:
  243. file.directory:
  244. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  245. - makedirs: true
  246. - require:
  247. - pkg: icinga2
  248. Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/:
  249. file.directory:
  250. - name: /etc/icinga2/ffho-conf.d/net/wbbl/
  251. - clean: true
  252. - watch_in:
  253. - service: icinga2
  254. # Generate config files for every WBBL device known to pillar
  255. {% for link_id, link_config in salt['pillar.get']('net:wbbl', {}).items () %}
  256. /etc/icinga2/ffho-conf.d/net/wbbl/{{ link_id }}.conf:
  257. file.managed:
  258. - source: salt://icinga2/wbbl.conf.tmpl
  259. - template: jinja
  260. - context:
  261. link_id: {{ link_id }}
  262. link_config: {{ link_config }}
  263. - require:
  264. - file: Create /etc/icinga2/ffho-conf.d/net/wbbl/
  265. - require_in:
  266. - file: Cleanup /etc/icinga2/ffho-conf.d/net/wbbl/
  267. - watch_in:
  268. - service: icinga2
  269. {% endfor %}
  270. ################################################################################
  271. # Icinga2 Client #
  272. ################################################################################
  273. {% else %}
  274. # Nodes should accept config and commands from Icinga2 server
  275. /etc/icinga2/features-available/api.conf:
  276. file.managed:
  277. - source: salt://icinga2/api.conf
  278. - require:
  279. - pkg: icinga2
  280. - watch_in:
  281. - service: icinga2
  282. # Client should not notify by themselves
  283. /etc/icinga2/features-enabled/notification.conf:
  284. file.absent:
  285. - require:
  286. - pkg: icinga2
  287. - watch_in:
  288. - service: icinga2
  289. {% endif %}
  290. ################################################################################
  291. # Check related stuff #
  292. ################################################################################
  293. salt-cron-state-apply:
  294. cron.present:
  295. - identifier: SALT_CRON_STATE_APPLY
  296. - name: "/usr/bin/salt-call state.highstate --state-verbose=False test=True > /var/cache/salt/state_apply.tmp 2>/dev/null ; mv /var/cache/salt/state_apply.tmp /var/cache/salt/state_apply"
  297. - user: root
  298. - minute: random
  299. - hour: "*/6"