Book Image

Mastering Puppet 5

By : Ryan Russell-Yates, Jason Southgate
Book Image

Mastering Puppet 5

By: Ryan Russell-Yates, Jason Southgate

Overview of this book

Puppet is a configuration management system and a language written for and by system administrators to manage a large number of systems efficiently and prevent configuration drift. The core topics this book addresses are Puppet's latest features and mastering Puppet Enterprise. You will begin by writing a new Puppet module, gaining an understanding of the guidelines and style of the Puppet community. Following on from this, you will take advantage of the roles and profiles pattern, and you will learn how to structure your code. Next, you will learn how to extend Puppet and write custom facts, functions, types, and providers in Ruby, and also use the new features of Hiera 5. You will also learn how to configure the new Code Manager component, and how to ensure code is automatically deployed to (multiple) Puppet servers. Next, you will learn how to integrate Puppet with Jenkins and Git to build an effective workflow for multiple teams, and use the new Puppet Tasks feature and the latest Puppet Orchestrator language extensions. Finally, you will learn how to scale and troubleshoot Puppet. By the end of the book, you will be able to deal with problems of scale and exceptions in your code, automate workflows, and support multiple developers working simultaneously.
Table of Contents (19 chapters)
Title Page
Dedication
Packt Upsell
Contributors
Preface
Index

Encrypted YAML backend


In Puppet 4.9.3, a hiera-eyaml backend was added to the Hiera functionality, allowing you to store encrypted data values. So, you can now hide away all your secret values, such as passwords, certificates, and so on, rather than using plain text in your Hiera data files. Let's go through the steps you can take to get this facility up and running.

 

Installing hiera-eyaml

To set up eyaml with Puppet Server, install the hiera-eyaml gem with the following command:

$ sudo /opt/puppetlabs/bin/puppetserver gem install hiera-eyaml

You'll also need to install the Ruby gem a second time with the following command:

$ sudo /opt/puppetlabs/puppet/bin/gem install hiera-eyaml

Creating the encryption keys

Use the eyaml createkeys command to create the public and private encryption keys, as follows:

$ eyaml createkeys

This command will create the public and private keys with their default names in the default  ./keys directory.

Securely storing away the encryption keys

Let's now copy the two keys...