Por que Hiera não está encontrando o ambiente, e também não é fantoche

1

Dados estes arquivos:

# find /etc/puppetlabs/code -type f | grep -v modules | xargs head -n 100
==> /etc/puppetlabs/code/environments/production/hieradata/common.yaml <==
pgwatch:
  password: "mypass1"
puppetdb:
  password: "mypass2"

==> /etc/puppetlabs/code/environments/production/manifests/site.pp <==
node "todd.ca.seevibes.com" {
  class { 'postgresql::globals':
    encoding            => 'UTF-8',
    locale              => 'en_US.UTF-8',
    manage_package_repo => true,
    version             => '9.1',
  } -> class{'postgresql::server':
  } -> postgresql::server::db{'puppetdb':
    user     => 'puppetdb',
    password => postgresql_password('puppetdb', hiera('puppetdb::password')),
  } -> postgresql::server::db{'pgwatch':
    user     => 'pgwatch',
    password => postgresql_password('pgwatch', hiera('pgwatch::password')),
  }

  postgresql::server::pg_hba_rule{'allow pgwatch from anywhere':
    address     => '0.0.0.0/32',
    auth_method => 'md5',
    database    => 'pgwatch',
    user        => 'pgwatch',
  }
}

==> /etc/puppetlabs/code/hiera.yaml <==
---
:backends:
  - json
  - yaml
:yaml:
  # Use the default value for datadir
  :datadir:
:json:
  # Use the default value for datadir
  :datadir:
:hierarchy:
  - "node/%{::fqdn}"
  - "node/%{::hostname}"
  - "%{::domain}"
  - common

Eu esperava que o seguinte retornasse o valor pgwatch::password :

# hiera --debug pgwatch::password
DEBUG: 2015-12-09 22:35:06 +0000: Hiera JSON backend starting
DEBUG: 2015-12-09 22:35:06 +0000: Looking up pgwatch::password in JSON backend
DEBUG: 2015-12-09 22:35:06 +0000: Looking for data source common
DEBUG: 2015-12-09 22:35:06 +0000: Cannot find datafile /etc/puppetlabs/code/environments//hieradata/common.json, skipping
DEBUG: 2015-12-09 22:35:06 +0000: Hiera YAML backend starting
DEBUG: 2015-12-09 22:35:06 +0000: Looking up pgwatch::password in YAML backend
DEBUG: 2015-12-09 22:35:06 +0000: Looking for data source common
DEBUG: 2015-12-09 22:35:06 +0000: Cannot find datafile /etc/puppetlabs/code/environments//hieradata/common.yaml, skipping
nil

A mesma consulta do Puppet também falha:

# puppet agent -t
Info: Using configured environment 'production'
Info: Retrieving pluginfacts
Info: Retrieving plugin
Info: Loading facts
Error: Could not retrieve catalog from remote server: Error 400 on SERVER: Evaluation Error: Error while evaluating a Function Call, Could not find data item puppetdb::password in any Hiera data file and no default supplied at /etc/puppetlabs/code/environments/production/manifests/site.pp:10:49 on node todd.ca.seevibes.com
Warning: Not using cache on failed catalog
Error: Could not retrieve catalog; skipping run

No log de depuração do hiera, podemos ver claramente o ambiente ausente nos caminhos de pesquisa: /etc/puppetlabs/code/environments//hieradata/common.json (observe o duplo // antes de hieradata ).

Encontrei Como especifico $ environment para Hiera na linha de comando? cuja melhor resposta diz para passar ::environment=production , que nada muda. Quando eu passo environment=production , a pesquisa "é bem-sucedida", mas não retorna nada:

# hiera --debug pgwatch::password 'environment=production'
DEBUG: 2015-12-09 22:42:12 +0000: Hiera JSON backend starting
DEBUG: 2015-12-09 22:42:12 +0000: Looking up pgwatch::password in JSON backend
DEBUG: 2015-12-09 22:42:12 +0000: Looking for data source common
DEBUG: 2015-12-09 22:42:12 +0000: Cannot find datafile /etc/puppetlabs/code/environments/production/hieradata/common.json, skipping
DEBUG: 2015-12-09 22:42:12 +0000: Hiera YAML backend starting
DEBUG: 2015-12-09 22:42:12 +0000: Looking up pgwatch::password in YAML backend
DEBUG: 2015-12-09 22:42:12 +0000: Looking for data source common
nil

Acredito que, desta vez, o caminho estava correto e o arquivo de dados foi encontrado, mas o valor não foi retornado.

Eu estava esperando uma corrida Puppet para encontrar o valor. O que estou fazendo errado?

# uname -a
Linux todd 3.10.23-xxxx-grs-ipv6-64 #1 SMP Mon Dec 9 16:02:37 CET 2013 x86_64 x86_64 x86_64 GNU/Linux
# puppet --version
4.3.1
# hiera --version
3.0.5
# puppet agent --configprint environment
production
# which puppet
/opt/puppetlabs/bin/puppet
# which hiera
/opt/puppetlabs/bin/hiera
    
por François Beausoleil 09.12.2015 / 23:52

1 resposta

5

no seu arquivo /etc/puppetlabs/code/environments/production/hieradata/common.yaml , você precisa escrever puppetdb::password: mypass2

Na sintaxe yaml, isso é um hash e não uma variável simples

puppetdb:
  password: "mypass2"

Desta forma, você tem uma variável simples

puppetdb::password: mypass2
    
por 10.12.2015 / 01:11

Tags