icingadb
Version information
This version is compatible with:
- Puppet Enterprise 2023.8.x, 2023.7.x, 2023.6.x, 2023.5.x, 2023.4.x, 2023.3.x, 2023.2.x, 2023.1.x, 2023.0.x, 2021.7.x, 2021.6.x, 2021.5.x, 2021.4.x, 2021.3.x
- Puppet >= 7.9.0 < 9.0.0
- , , , , ,
Start using this module
Add this module to your Puppetfile:
mod 'puppet-icingadb', '3.1.1'
Learn more about managing modules with a PuppetfileDocumentation
icingadb
Table of Contents
Description
This module manages the IcingaDB Redis server and the IcingaDB itself.
Setup
What the IcingaDB Puppet module supports
- Management of the IcingaDB Redis
- and the icingaDB itself
Setup Requirements
This module supports:
- [puppet] >= 7.9.0 < 9.0.0
And requiers:
- [puppetlabs/stdlib] >= 6.6.0 < 10.0.0
- [icinga/icinga] >= 2.9.0 < 6.0.0
Beginning with icingadb
Add this declaration to your Puppetfile:
mod 'icingadb',
:git => 'https://github.com/icinga/puppet-icingadb.git',
:tag => 'v1.0.0'
Then run:
bolt puppetfile install
Or do a git clone
by hand into your modules directory:
git clone https://github.com/voxpupuli/puppet-icingadb.git icingadb
Change to icingadb
directory and check out your desired version:
cd icingadb
git checkout v1.0.0
Reference
See REFERENCE.md
Release Notes
This code is a very early release and may still be subject to significant changes.
Transfer Notice
This plugin was originally authored by Icinga. The maintainer preferred that Vox Pupuli take ownership of the module for future improvement and maintenance. Existing pull requests and issues were transferred over, please fork and continue to contribute here instead of Icinga.
Previously: https://github.com/icinga/puppet-icingadb
Reference
Table of Contents
Classes
Public Classes
icingadb
: Puppet class to manage IcingaDB.icingadb::globals
: This class loads the default parameters by doing a hiera lookup.icingadb::redis
: Manage the IcingaDB Redis server.icingadb::redis::globals
: This class loads the default parameters by doing a hiera lookup.
Private Classes
icingadb::config
: A short summary of the purpose of this class Configures IcingaDBicingadb::install
: Installs IcingaDBicingadb::install::db
: Imports IcingaDB database schemaicingadb::redis::config
: Configures IcingaDB Redis servericingadb::redis::install
: Installs IcingaDB Redis servericingadb::redis::service
: Manage IcingaDB Redis server serviceicingadb::service
: Manage IcingaDB service
Data types
IcingaDB::DBOptions
: Data type for options to connect the IcingaDB database.IcingaDB::LoggingOptions
: Logging options data type for the IcingaDB process.IcingaDB::RetentionOptions
: Data type for retention options of the connection to the IcingaDB database.
Classes
icingadb
Puppet class to manage IcingaDB.
Examples
class { 'icingadb':
manage_repos => true,
db_type => 'pgsql',
db_password => 'supersecret',
import_schema => true,
}
Parameters
The following parameters are available in the icingadb
class:
ensure
enable
manage_repos
manage_packages
redis_host
redis_port
redis_password
redis_use_tls
redis_tls_insecure
redis_tls_cert
redis_tls_cert_file
redis_tls_key
redis_tls_key_file
redis_tls_cacert
redis_tls_cacert_file
db_type
db_host
db_port
db_name
db_username
db_password
import_schema
db_use_tls
db_tls_insecure
db_tls_cert
db_tls_cert_file
db_tls_key
db_tls_key_file
db_tls_cacert
db_tls_cacert_file
db_options
logging_level
logging_output
logging_interval
logging_options
retention_history_data
retention_sla_data
retention_options
ensure
Data type: Enum['running', 'stopped']
Choose wether the service is running
or stopped
.
Default value: 'running'
enable
Data type: Boolean
Choose wether the service has to start at boot.
Default value: true
manage_repos
Data type: Boolean
Whether to involve the Icinga repositories.
Default value: false
manage_packages
Data type: Boolean
Whether to manage the IcingaDB packages.
Default value: true
redis_host
Data type: Stdlib::Host
Redis server to connect.
Default value: 'localhost'
redis_port
Data type: Stdlib::Port
Port on the Redis host to connect.
Default value: 6380
redis_password
Data type: Optional[Icinga::Secret]
Passwort to login into redis.
Default value: undef
redis_use_tls
Data type: Optional[Boolean]
Wether or not to enable tls encryption to connect the database.
Default value: undef
redis_tls_insecure
Data type: Optional[Boolean]
Disable the server certificate validation. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_cert
Data type: Optional[String[1]]
Client certificate in PEM format. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_cert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the client certificate. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_key
Data type: Optional[Icinga::Secret]
Client private key in PEM format. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_key_file
Data type: Optional[Stdlib::Absolutepath]
Location of the client private key. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_cacert
Data type: Optional[String[1]]
CA root certificate in PEM format. Only valid if redis_use_tls
is turned on.
Default value: undef
redis_tls_cacert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the CA root certificate. Only valid if redis_use_tls
is turned on.
Default value: undef
db_type
Data type: Enum['mysql','pgsql']
Choose wether MySQL or PostgreSQL as backend for historical data.
Default value: 'mysql'
db_host
Data type: Stdlib::Host
Database server.
Default value: 'localhost'
db_port
Data type: Optional[Stdlib::Port]
Port to connect the database.
Default value: undef
db_name
Data type: String[1]
The IcingaDB database.
Default value: 'icingadb'
db_username
Data type: String[1]
User that is used to connect the database.
Default value: 'icingadb'
db_password
Data type: Icinga::Secret
Passwort to login into database.
import_schema
Data type: Variant[Boolean, Enum['mariadb', 'mysql']]
Whether or not to import the databse schema or not. Options mariadb
and mysql
,
both means true. With mariadb its cli options are used for the import,
whereas with mysql its different options.
Default value: false
db_use_tls
Data type: Optional[Boolean]
Wether or not to enable tls encryption to connect the database.
Default value: undef
db_tls_insecure
Data type: Optional[Boolean]
Disable the server certificate validation. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_cert
Data type: Optional[String[1]]
Client certificate in PEM format. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_cert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the client certificate. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_key
Data type: Optional[Icinga::Secret]
Client private key in PEM format. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_key_file
Data type: Optional[Stdlib::Absolutepath]
Location of the client private key. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_cacert
Data type: Optional[String[1]]
CA root certificate in PEM format. Only valid if db_use_tls
is turned on.
Default value: undef
db_tls_cacert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the CA root certificate. Only valid if db_use_tls
is turned on.
Default value: undef
db_options
Data type: IcingaDB::DBOptions
List of low-level database options that can be set to influence some Icinga DB internal default behaviours.
Default value: {}
logging_level
Data type: Enum['fatal','error','warn','info','debug']
Specifies the default logging level. Can be set to fatal, error, warn, info or debug.
Default value: 'info'
logging_output
Data type: Optional[Enum['console','systemd-journald']]
Configures the logging output. Can be set to console (stderr) or systemd-journald.
Default value: undef
logging_interval
Data type: Pattern[/^\d+\.?\d*[d|h|m|s]?$/]
Interval for periodic logging defined as duration string.
Default value: '20s'
logging_options
Data type: IcingaDB::LoggingOptions
Map of component-logging level pairs to define a different log level than the default value for each component.
Default value: {}
retention_history_data
Data type: Optional[Integer[1]]
Number of days to retain full historical data.
Default value: undef
retention_sla_data
Data type: Optional[Integer[1]]
Number of days to retain historical data for SLA reporting.
Default value: undef
retention_options
Data type: IcingaDB::RetentionOptions
Map of history category to number of days to retain its data in order to
enable retention only for specific categories or to override the number
that has been configured in retention_history_data
.
Default value: {}
icingadb::globals
This class loads the default parameters by doing a hiera lookup.
Parameters
The following parameters are available in the icingadb::globals
class:
package_name
Data type: String[1]
service_name
Data type: String[1]
user
Data type: String[1]
group
Data type: String[1]
conf_dir
Data type: Stdlib::Absolutepath
mysql_db_schema
Data type: Stdlib::Absolutepath
pgsql_db_schema
Data type: Stdlib::Absolutepath
icingadb::redis
Manage the IcingaDB Redis server.
Examples
Enable required repositories, bind Redis on Port 6380
(default) on localhost and increase keepalive and number of databases.
class { 'icingadb::redis':
manage_repos => true,
bind => '127.0.0.1',
port => 6380,
config => {
tcp_keepalive => 400,
databases => 8,
}
}
Bind Redis to port 6380 an for encrypted connections to 6381 (default) on localhost and the main interface. Also force an authentication by password.
class { 'icingadb::redis':
bind => ['127.0.0.1', $::ipaddress],
requirepass => Sensitive('supersecret'),
use_tls => true,
tls_port => 6381,
tls_cert_file => '/etc/icingadb-redis/server.crt',
tls_key_file => '/etc/icingadb-redis/server.key',
tls_cacert_file => '/etc/icingadb-redis/ca.crt',
}
Bind Redis for encrypted only connections to 6380 on localhost and the main interface. Also force a valid client certificate for authentication.
class { 'icingadb::redis':
bind => ['127.0.0.1', $::ipaddress],
use_tls => true,
tls_port => 6380,
tls_cert_file => '/etc/icingadb-redis/server.crt',
tls_key_file => '/etc/icingadb-redis/server.key',
tls_cacert_file => '/etc/icingadb-redis/ca.crt',
tls_auth_clients => 'yes',
}
Parameters
The following parameters are available in the icingadb::redis
class:
ensure
enable
bind
port
manage_repos
manage_packages
requirepass
use_tls
tls_port
tls_cert
tls_key
tls_cacert
tls_cert_file
tls_key_file
tls_cacert_file
tls_auth_clients
config
ensure
Data type: Enum['running','stopped']
Choose wether the service is running
or stopped
.
Default value: 'running'
enable
Data type: Boolean
Choose wether the service has to start at boot.
Default value: true
bind
Data type: Variant[Stdlib::Host,Array[Stdlib::Host]]
Configure which IP address(es) to listen on. To bind on all interfaces, use an empty array.
Default value: ['127.0.0.1', '::1']
port
Data type: Stdlib::Port
Configure which port to listen on.
Default value: 6380
manage_repos
Data type: Boolean
Whether to involve the Icinga repositories.
Default value: false
manage_packages
Data type: Boolean
Whether or not to manage the IcingaDB packages.
Default value: true
requirepass
Data type: Optional[Icinga::Secret]
Require clients to issue AUTH before processing any other commands.
Default value: undef
use_tls
Data type: Optional[Boolean]
Wether or not to enable tls encryption.
Default value: undef
tls_port
Data type: Stdlib::Port
Configure which port to listen on for tls encrypted connection. Only valid if use_tls
is turned on.
Default value: 6381
tls_cert
Data type: Optional[String[1]]
Certificate in PEM format. Only valid if use_tls
is turned on.
Default value: undef
tls_key
Data type: Optional[Icinga::Secret]
Private key in PEM format. Only valid if use_tls
is turned on.
Default value: undef
tls_cacert
Data type: Optional[String[1]]
The CA root certificate in PEM format. Only valid if use_tls
is turned on.
Default value: undef
tls_cert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the certificate file. Only valid if use_tls
is turned on.
Default value: undef
tls_key_file
Data type: Optional[Stdlib::Absolutepath]
Location of the private key file. Only valid if use_tls
is turned on.
Default value: undef
tls_cacert_file
Data type: Optional[Stdlib::Absolutepath]
Location of the CA root certificate. Only valid if use_tls
is turned on.
Default value: undef
tls_auth_clients
Data type: Optional[Enum['yes', 'no', 'optional']]
Set to yes
to force authentication with a valid client certificate.
Other Options are no
and optional
. Only valid if use_tls
is turned on.
Default value: undef
config
Data type: Hash[String[1], Any]
Other parameters that can be set, see redis::instance.
Default value: {}
icingadb::redis::globals
This class loads the default parameters by doing a hiera lookup.
Parameters
The following parameters are available in the icingadb::redis::globals
class:
package_name
Data type: String[1]
service_name
Data type: String[1]
user
Data type: String[1]
group
Data type: String[1]
redis_bin
Data type: Stdlib::Absolutepath
conf_dir
Data type: Stdlib::Absolutepath
work_dir
Data type: Stdlib::Absolutepath
run_dir
Data type: Stdlib::Absolutepath
log_dir
Data type: Stdlib::Absolutepath
Data types
IcingaDB::DBOptions
Data type for options to connect the IcingaDB database.
Alias of
Hash[Enum[
'max_connections',
'max_connections_per_table',
'max_placeholders_per_statement',
'max_rows_per_transaction',
'wsrep_sync_wait'
], Integer[0]]
IcingaDB::LoggingOptions
Logging options data type for the IcingaDB process.
Alias of
Hash[Enum[
'config-sync','database','dump-signals',
'heartbeat','high-availability',
'history-sync','overdue-sync','redis',
'retention','runtime-updates','telemetry'
], Enum['fatal','error','warn','info','debug']]
IcingaDB::RetentionOptions
Data type for retention options of the connection to the IcingaDB database.
Alias of
Hash[Enum[
'acknowledgement','comment','downtime',
'flapping','notification','state'
], Integer[1]]
Changelog
All notable changes to this project will be documented in this file. Each new release typically also includes the latest modulesync defaults. These should not affect the functionality of the module.
v3.1.1 (2024-10-18)
Fixed bugs:
- Fix #43 add missing redis module dependency #45 (lbetz)
- fix #35 allow null values in dboptions #44 (lbetz)
v3.1.0 (2024-09-24)
Implemented enhancements:
- Add new data type for db options #40 (lbetz)
- Add new data type for retention options #39 (lbetz)
- Add new data type for logging options #38 (lbetz)
- Replace config template by conversion to yaml #37 (lbetz)
- Add missing database options in class icingadb #36 (lbetz)
v3.0.0 (2024-08-15)
Breaking changes:
- Drop EOL CentOS 8 support #29 (lbetz)
- remove Debian Buster support #26 (lbetz)
- remove support of EL7 platforms #25 (lbetz)
Implemented enhancements:
- Set requirement of puppet-icinga to >= 3.0.0 #31 (lbetz)
- Restrict params to non-empty strings, replace to Icinga::Secret datatype #30 (lbetz)
- Add Ubuntu Noble (24.04) support #28 (lbetz)
- Add Fedora 40 support #27 (lbetz)
Fixed bugs:
v2.0.1 (2024-07-02)
Fixed bugs:
Merged pull requests:
- fixtures.yml: Pull dependencies from git #18 (bastelfreak)
v2.0.0 (2024-05-23)
Breaking changes:
Implemented enhancements:
v1.0.1 (2023-07-20)
Fixed bugs:
- Duplicate declaration of Icinga::Cert[icingadb tls files for the database client connect] #8
v1.0.0 (2022-12-27)
Implemented enhancements:
- Rework management of icingadb to support the released version #3
Fixed bugs:
Closed issues:
v0.1.0 (2020-04-21)
* This Changelog was automatically generated by github_changelog_generator
Dependencies
- puppetlabs/stdlib (>= 6.6.0 < 10.0.0)
- puppet/redis (>= 8.2.0 < 12.0.0)
- puppet/icinga (>= 3.0.0 < 7.0.0)
Apache License Version 2.0, January 2004 http://www.apache.org/licenses/ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 1. Definitions. "License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document. "Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License. "Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity. "You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License. "Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files. "Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types. "Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work (an example is provided in the Appendix below). "Derivative Works" shall mean any work, whether in Source or Object form, that is based on (or derived from) the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For the purposes of this License, Derivative Works shall not include works that remain separable from, or merely link (or bind by name) to the interfaces of, the Work and Derivative Works thereof. "Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For the purposes of this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems that are managed by, or on behalf of, the Licensor for the purpose of discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution." "Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work. 2. Grant of Copyright License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form. 3. Grant of Patent License. Subject to the terms and conditions of this License, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated in this section) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work to which such Contribution(s) was submitted. If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed. 4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions: (a) You must give any other recipients of the Work or Derivative Works a copy of this License; and (b) You must cause any modified files to carry prominent notices stating that You changed the files; and (c) You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and (d) If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding those notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or, within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License. You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License. 5. Submission of Contributions. Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Notwithstanding the above, nothing herein shall supersede or modify the terms of any separate license agreement you may have executed with Licensor regarding such Contributions. 6. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except as required for reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file. 7. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License. 8. Limitation of Liability. In no event and under no legal theory, whether in tort (including negligence), contract, or otherwise, unless required by applicable law (such as deliberate and grossly negligent acts) or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages of any character arising as a result of this License or out of the use or inability to use the Work (including but not limited to damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses), even if such Contributor has been advised of the possibility of such damages. 9. Accepting Warranty or Additional Liability. While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations and/or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor by reason of your accepting any such warranty or additional liability. END OF TERMS AND CONDITIONS APPENDIX: How to apply the Apache License to your work. To apply the Apache License to your work, attach the following boilerplate notice, with the fields enclosed by brackets "[]" replaced with your own identifying information. (Don't include the brackets!) The text should be enclosed in the appropriate comment syntax for the file format. We also recommend that a file or class name and description of purpose be included on the same "printed page" as the copyright notice for easier identification within third-party archives. Copyright [yyyy] [name of copyright owner] Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.