puppet-eid/manifests/oidf_service.pp
2025-04-23 13:09:36 +02:00

29 lines
996 B
Puppet

# oidcfedservice
class eidas::oidf_service(
String $image_tag,
Enum['sandbox'] $enviroment,
Integer $service_port = 2000,
String $server_fqdn = $facts['networking']['fqdn'],
) {
$keystore_password = lookup('keystore_password', String, undef, undef)
ensure_resource('sunet::misc::create_dir', '/opt/oidf_service/config/', { owner => 'root', group => 'root', mode => '0750'})
file { '/opt/oidf_service/config/application.yml':
content => template("eidas/oidf_service/application-${enviroment}.yml.erb"),
mode => '0755',
}
if lookup("oidf_service_key", undef, undef, undef) != undef {
sunet::snippets::secret_file { "/opt/oidf_service/oidf_service.key": hiera_key => "oidf_service_key" }
# assume cert is in cosmos repo
} else {
# make key pair
sunet::snippets::keygen {"oidf_service_key":
key_file => "/opt/oidf_service/oidf_service.key",
cert_file => "/opt/oidf_service/oidf_service.pem"
}
}
}