]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
Configure unbound forwarders unless we are recursive
authorPeter Palfrader <peter@palfrader.org>
Wed, 2 Mar 2011 15:25:20 +0000 (16:25 +0100)
committerPeter Palfrader <peter@palfrader.org>
Wed, 2 Mar 2011 15:26:54 +0000 (16:26 +0100)
modules/puppetmaster/lib/puppet/parser/functions/nodeinfo.rb
modules/unbound/templates/unbound.conf.erb

index f08405080e528d649bd3129c50a8f13467049ff4..04da08068509219581c4713ceab8b051ea454a53 100644 (file)
@@ -32,6 +32,17 @@ module Puppet::Parser::Functions
       end
     end
 
+    if not nodeinfo['hoster']['nameservers'] or nodeinfo['hoster']['nameservers'].empty?
+      # no nameservers known for this hoster
+      results['misc']['resolver-recursive'] = true
+    elsif (nodeinfo['hoster']['nameservers'] & nodeinfo['misc']['v4addrs']).size > 0 or
+          (nodeinfo['hoster']['nameservers'] & nodeinfo['misc']['v6addrs']).size > 0
+      # this host is listed as a nameserver at this location
+      results['misc']['resolver-recursive'] = true
+    else
+      results['misc']['resolver-recursive'] = false
+    end
+
     return(results)
   end
 end
index 35610496c77cfaf5bf87429d22b2cc0177fca52a..ebda9f80b1de8ddaba5a83ac681d0f7eac5a1a9c 100644 (file)
@@ -54,7 +54,17 @@ server:
        auto-trust-anchor-file: "/var/lib/unbound/root.key"
        auto-trust-anchor-file: "/var/lib/unbound/debian.org.key"
 
-#forward-zone:
-#      name: "."
-#      forward-addr: 192.0.2.1
-#      forward-addr: 192.0.2.199
+<%=
+       out = []
+       unless results['misc']['resolver-recursive']
+               forwarders = nodeinfo['hoster']['nameservers']
+               forwarders ||= []
+
+               out << 'forward-zone:'
+               out << '        name: "."'
+               forwarders.each do |ns|
+                       out << "        forward-addr: #{ns}"
+               end
+       end
+       out.join("\n")
+%>