Skip to content

Commit c23177b

Browse files
committed
fix: update extra options and remove stale dropin
Signed-off-by: Sidharth Jawale <sidharth@obmondo.com>
1 parent 51e16d5 commit c23177b

File tree

1 file changed

+16
-10
lines changed
  • modules/enableit/common/manifests/monitor/exporter

1 file changed

+16
-10
lines changed

modules/enableit/common/manifests/monitor/exporter/security.pp

Lines changed: 16 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,6 @@
3232
Stdlib::HTTPUrl $vuls_server_url = 'https://vuls.obmondo.com',
3333
Stdlib::Absolutepath $config_file = "${common::monitor::exporter::config_dir}/security_exporter.yaml",
3434
) {
35-
3635
unless $enable { return() }
3736

3837
$service_name = 'obmondo-security-exporter'
@@ -68,7 +67,7 @@
6867
package_ensure => ensure_latest($enable),
6968
init_style => $facts['service_provider'],
7069
install_method => 'package',
71-
options => "-config=${config_file}",
70+
options => "serve --config=${config_file}",
7271
tag => $::trusted['certname'],
7372
notify_service => Service[$service_name],
7473
group => 'root',
@@ -88,18 +87,25 @@
8887
group => 'root',
8988
mode => '0640',
9089
content => stdlib::to_yaml({
91-
'vuls_server' => {
92-
'url' => $vuls_server_url,
93-
'timeout' => '5m',
94-
'cert_file' => "/etc/puppetlabs/puppet/ssl/certs/${host}.pem",
95-
'key_file' => "/etc/puppetlabs/puppet/ssl/private_keys/${host}.pem",
96-
},
97-
'listen_address' => "${listen_host}:${listen_port}",
98-
'scan_interval' => '12h',
90+
'vuls_server' => {
91+
'url' => $vuls_server_url,
92+
'timeout' => '5m',
93+
'cert_file' => "/etc/puppetlabs/puppet/ssl/certs/${host}.pem",
94+
'key_file' => "/etc/puppetlabs/puppet/ssl/private_keys/${host}.pem",
95+
},
96+
'listen_address' => "${listen_host}:${listen_port}",
97+
'scan_interval' => '12h',
9998
}),
10099
notify => Service["${service_name}.service"],
101100
}
102101

102+
systemd::dropin_file { "${service_name}_dropin":
103+
ensure => 'absent',
104+
filename => "${service_name}-override.conf",
105+
unit => "${service_name}.service",
106+
notify_service => false,
107+
}
108+
103109
# NOTE: This is a daemon-reload, which will do a daemon-reload in noop mode.
104110
# upstream module cant handle noop. (which is correct)
105111
Exec <| tag == 'systemd-obmondo-security-exporter.service-systemctl-daemon-reload' |> {

0 commit comments

Comments
 (0)