|
1 | 1 | # == Class vault::install
|
2 | 2 | #
|
3 | 3 | class vault::install {
|
| 4 | + |
4 | 5 | $vault_bin = "${::vault::bin_dir}/vault"
|
5 | 6 |
|
6 | 7 | case $::vault::install_method {
|
7 |
| - 'archive': { |
8 |
| - if $::vault::manage_download_dir { |
9 |
| - file { $::vault::download_dir: |
10 |
| - ensure => directory, |
11 |
| - } |
| 8 | + 'archive': { |
| 9 | + if $::vault::manage_download_dir { |
| 10 | + file { $::vault::download_dir: |
| 11 | + ensure => directory, |
12 | 12 | }
|
| 13 | + } |
13 | 14 |
|
14 |
| - archive { "${::vault::download_dir}/${::vault::download_filename}": |
15 |
| - ensure => present, |
16 |
| - extract => true, |
17 |
| - extract_path => $::vault::bin_dir, |
18 |
| - source => $::vault::real_download_url, |
19 |
| - cleanup => true, |
20 |
| - creates => $vault_bin, |
21 |
| - before => File['vault_binary'], |
22 |
| - } |
| 15 | + $_manage_file_capabilities = true |
| 16 | + $_vault_versioned_bin = "/opt/vault-${::vault::version}/vault" |
| 17 | + |
| 18 | + file { "/opt/vault-${::vault::version}": |
| 19 | + ensure => directory, |
| 20 | + owner => 'root', |
| 21 | + group => 'root', |
| 22 | + mode => '0755', |
| 23 | + } |
| 24 | + |
| 25 | + archive { "${::vault::download_dir}/${::vault::download_filename}": |
| 26 | + ensure => present, |
| 27 | + extract => true, |
| 28 | + extract_path => "/opt/vault-${::vault::version}", |
| 29 | + source => $::vault::real_download_url, |
| 30 | + cleanup => true, |
| 31 | + creates => $_vault_versioned_bin, |
| 32 | + before => File['vault_binary'], |
| 33 | + } |
23 | 34 |
|
24 |
| - $_manage_file_capabilities = true |
| 35 | + file { 'vault_binary': |
| 36 | + path => $vault_bin, |
| 37 | + target => $_vault_versioned_bin, |
| 38 | + owner => 'root', |
| 39 | + group => 'root', |
| 40 | + mode => '0755', |
| 41 | + notify => Class['vault::service'], |
25 | 42 | }
|
26 | 43 |
|
| 44 | + } |
| 45 | + |
27 | 46 | 'repo': {
|
28 | 47 | package { $::vault::package_name:
|
29 | 48 | ensure => $::vault::package_ensure,
|
30 | 49 | }
|
31 | 50 | $_manage_file_capabilities = false
|
| 51 | + $_vault_versioned_bin = undef |
| 52 | + |
| 53 | + file { 'vault_binary': |
| 54 | + path => $vault_bin, |
| 55 | + owner => 'root', |
| 56 | + group => 'root', |
| 57 | + mode => '0755', |
| 58 | + } |
32 | 59 | }
|
33 | 60 |
|
34 | 61 | default: {
|
35 | 62 | fail("Installation method ${::vault::install_method} not supported")
|
36 | 63 | }
|
37 | 64 | }
|
38 | 65 |
|
39 |
| - file { 'vault_binary': |
40 |
| - path => $vault_bin, |
41 |
| - owner => 'root', |
42 |
| - group => 'root', |
43 |
| - mode => '0755', |
44 |
| - } |
45 |
| - |
46 | 66 | if !$::vault::disable_mlock and pick($::vault::manage_file_capabilities, $_manage_file_capabilities) {
|
47 | 67 | file_capability { 'vault_binary_capability':
|
48 | 68 | ensure => present,
|
49 |
| - file => $vault_bin, |
| 69 | + file => pick($_vault_versioned_bin, $vault_bin), |
50 | 70 | capability => 'cap_ipc_lock=ep',
|
51 | 71 | subscribe => File['vault_binary'],
|
52 | 72 | }
|
|
0 commit comments