]> git.donarmstrong.com Git - dsa-puppet.git/blob - modules/dacs/manifests/init.pp
fb0cf1b362a1a8068ff6a9151c7bf0b1be9dd7d0
[dsa-puppet.git] / modules / dacs / manifests / init.pp
1 # = Class: dacs
2 #
3 # This class installs and configures dacs for web auth
4 #
5 # == Sample Usage:
6 #
7 #   include dacs
8 #
9 class dacs {
10         package { 'dacs':
11                 ensure => installed,
12         }
13         package { 'libapache2-mod-dacs':
14                 ensure => installed,
15         }
16
17         File {
18                 owner => root,
19                 group => www-data,
20                 mode  => '0640',
21         }
22
23         file { '/var/log/dacs':
24                 ensure  => directory,
25                 mode    => '0770',
26                 purge   => true,
27         }
28         file { [
29                         '/etc/dacs/federations',
30                         '/etc/dacs/federations/debian.org/',
31                         '/etc/dacs/federations/debian.org/DEBIAN',
32                         '/etc/dacs/federations/debian.org/DEBIAN/acls',
33                         '/etc/dacs/federations/debian.org/DEBIAN/groups',
34                         '/etc/dacs/federations/debian.org/DEBIAN/groups/DACS'
35                 ]:
36                 ensure  => directory,
37                 mode    => '0750',
38                 require => Package['libapache2-mod-dacs'],
39                 purge   => true
40         }
41         file { '/etc/logrotate.d/dacs':
42                 source  => 'puppet:///modules/dacs/common/dacs.logrotate',
43         }
44         file { '/etc/dacs/federations/site.conf':
45                 source  => 'puppet:///modules/dacs/common/site.conf',
46         }
47         file { '/etc/dacs/federations/debian.org/DEBIAN/dacs.conf':
48                 source  => [ "puppet:///modules/dacs/per-host/${::fqdn}/dacs.conf",
49                         'puppet:///modules/dacs/common/dacs.conf', ],
50         }
51         file { '/etc/dacs/federations/debian.org/DEBIAN/acls/revocations':
52                 source  => 'puppet:///modules/dacs/common/revocations',
53         }
54         file { '/etc/dacs/federations/debian.org/DEBIAN/groups/DACS/jurisdictions.grp':
55                 source  => 'puppet:///modules/dacs/common/jurisdictions.grp',
56         }
57         file { '/etc/dacs/federations/debian.org/DEBIAN/acls/acl-noauth.0':
58                 source  => [ "puppet:///modules/dacs/per-host/${::fqdn}/acl-noauth.0",
59                         'puppet:///modules/dacs/common/acl-noauth.0' ],
60                 notify  => Exec['dacsacl']
61         }
62         file { '/etc/dacs/federations/debian.org/DEBIAN/acls/acl-private.0':
63                 source  => [ "puppet:///modules/dacs/per-host/${::fqdn}/acl-private.0",
64                         'puppet:///modules/dacs/common/acl-private.0' ],
65                 notify  => Exec['dacsacl']
66         }
67         file { '/etc/dacs/federations/debian.org/federation_keyfile':
68                 source  => 'puppet:///modules/dacs/private/debian.org_federation_keyfile',
69         }
70         file { '/etc/dacs/federations/debian.org/DEBIAN/jurisdiction_keyfile':
71                 source  => 'puppet:///modules/dacs/private/DEBIAN_jurisdiction_keyfile',
72         }
73
74         exec { 'dacsacl':
75                 command     => 'dacsacl -sc /etc/dacs/federations/site.conf -c /etc/dacs/federations/debian.org/DEBIAN/dacs.conf -uj DEBIAN && chown root:www-data /etc/dacs/federations/debian.org/DEBIAN/acls/INDEX',
76                 refreshonly => true,
77         }
78
79 }