Puppet Concat片段validate_cmd配置问题:验证时机与参数报错
问题描述
核心需求:在Puppet中使用concat拼接证书文件后,针对order为01的tls_cert_file1执行验证脚本,仅当脚本返回0时才部署拼接后的文件,否则终止后续操作。
遇到两个问题:
- 在
concat资源上配置validate_cmd时,验证先于拼接执行,导致用客户端旧证书验证通过后再完成拼接,新证书内容未被检查。 - 在
concat::fragment上配置validate_cmd时,出现参数错误:Error: Could not retrieve catlog from remote server. Evaluation Error: while evaluating a Resource Statement, concat::fragment { 'tls_cert_file1': has no parameter named 'valdiate_cmd'
错误配置1(验证时机错误)
# Verification script file { 'tls_verification_script': ensure => file, path => "${config}/tls_verification", owner => 'nagios', group => 'nagios', content => template('nagios/tls_verification.erb'), } # Concatenation of certificates concat { 'tls_cert': ensure => present, path => $tls_path, owner => 'nagios', group => 'nagios', validate_cmd => "/usr/bin/python3 ${config}/tls_verification", } # Fragment for tls_cert_file1 concat::fragment { 'tls_cert_file1': target => 'tls_cert', source => "puppet:///module/xxxxxxxxxxxx", order => '01', } # Fragment for tls_cert_file2 concat::fragment { 'tls_cert_file2': target => 'tls_cert', source => "puppet:///modules/xxxxxxxxxxxx", order => '02', }
错误配置2(参数报错)
# Verification script file { 'tls_verification_script': ensure => file, path => "${config}/tls_verification", owner => 'nagios', group => 'nagios', content => template('nagios/tls_verification.erb'), } # Concatenation of certificates concat { 'tls_cert': ensure => present, path => $tls_path, owner => 'nagios', group => 'nagios', } # Fragment for tls_cert_file1 concat::fragment { 'tls_cert_file1': target => 'tls_cert', source => "puppet:///module/xxxxxxxxxxxx", order => '01', validate_cmd => "/usr/bin/python3 ${config}/tls_verification", } # Fragment for tls_cert_file2 concat::fragment { 'tls_cert_file2': target => 'tls_cert', source => "puppet:///modules/xxxxxxxxxxxx", order => '02', }
正确配置方案
要实现先拼接再验证的需求,需利用concat资源的validate_cmd占位符特性,确保验证脚本针对拼接后的临时文件检查,而非旧文件。具体配置如下:
# 验证脚本(修改为支持接收文件路径参数) file { 'tls_verification_script': ensure => file, path => "${config}/tls_verification", owner => 'nagios', group => 'nagios', mode => '0755', # 添加执行权限 content => template('nagios/tls_verification.erb'), } # 证书拼接配置(修正validate_cmd并添加依赖) concat { 'tls_cert': ensure => present, path => $tls_path, owner => 'nagios', group => 'nagios', validate_cmd => "/usr/bin/python3 ${config}/tls_verification %", # %代表拼接后的临时文件路径 require => File['tls_verification_script'], # 确保脚本先部署完成 } # 证书片段1(修正source路径拼写错误) concat::fragment { 'tls_cert_file1': target => 'tls_cert', source => "puppet:///modules/xxxxxxxxxxxx", order => '01', } # 证书片段2 concat::fragment { 'tls_cert_file2': target => 'tls_cert', source => "puppet:///modules/xxxxxxxxxxxx", order => '02', }
关键说明
%占位符的作用:concat资源的validate_cmd中,%会被自动替换为拼接过程中生成的临时文件路径,确保验证的是最新拼接后的内容,而非目标路径的旧文件。- 脚本适配:验证脚本需要调整为读取传入的文件参数(即
%对应的路径),比如Python脚本中用sys.argv[1]获取路径,读取内容后专门校验tls_cert_file1对应的部分。 - 依赖与权限:添加
require确保脚本在拼接前存在,同时给脚本设置执行权限0755,避免执行失败。 - 路径修正:原配置中
puppet:///module/为拼写错误,需改为puppet:///modules/才能正确读取模块文件。
内容的提问来源于stack exchange,提问作者sandy
相关产品推荐
相关产品推荐

