Skip to content

Commit 5c87f03

Browse files
committed
Define resource bacula::director::console
1 parent 36ae599 commit 5c87f03

5 files changed

Lines changed: 252 additions & 0 deletions

File tree

REFERENCE.md

Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@
1717
### Defined types
1818

1919
* [`bacula::director::client`](#bacula--director--client): Define a Bacula Director Client
20+
* [`bacula::director::console`](#bacula--director--console): Define a Bacula Director Console
2021
* [`bacula::director::fileset`](#bacula--director--fileset): Configure a Bacula Director Fileset
2122
* [`bacula::director::job`](#bacula--director--job): Configure a Bacula Director Job
2223
* [`bacula::director::pool`](#bacula--director--pool): Configure a Bacula Director Pool
@@ -1007,6 +1008,143 @@ The path to the bacula configuration directory
10071008

10081009
Default value: `$bacula::conf_dir`
10091010

1011+
### <a name="bacula--director--console"></a>`bacula::director::console`
1012+
1013+
This define creates a console declaration for the director.
1014+
Resources of this type are intended to manage conf.d/console.conf entries.
1015+
1016+
Aside from Director resource names and console command names,
1017+
the special keyword *all* can be specified in any of the above access control lists.
1018+
When this keyword is present, any resource or command name (which ever is appropriate) will be accepted.
1019+
1020+
#### Examples
1021+
1022+
#####
1023+
1024+
```puppet
1025+
bacula::director::console { 'Monitoring':
1026+
password => 'monitoring_password',
1027+
}
1028+
```
1029+
1030+
#### Parameters
1031+
1032+
The following parameters are available in the `bacula::director::console` defined type:
1033+
1034+
* [`conf_dir`](#-bacula--director--console--conf_dir)
1035+
* [`password`](#-bacula--director--console--password)
1036+
* [`jobacl`](#-bacula--director--console--jobacl)
1037+
* [`clientacl`](#-bacula--director--console--clientacl)
1038+
* [`storageacl`](#-bacula--director--console--storageacl)
1039+
* [`scheduleacl`](#-bacula--director--console--scheduleacl)
1040+
* [`poolacl`](#-bacula--director--console--poolacl)
1041+
* [`filesetacl`](#-bacula--director--console--filesetacl)
1042+
* [`catalogacl`](#-bacula--director--console--catalogacl)
1043+
* [`commandacl`](#-bacula--director--console--commandacl)
1044+
* [`whereacl`](#-bacula--director--console--whereacl)
1045+
1046+
##### <a name="-bacula--director--console--conf_dir"></a>`conf_dir`
1047+
1048+
Data type: `String`
1049+
1050+
The bacula configuration director. Should not need adjusting
1051+
1052+
Default value: `$bacula::conf_dir`
1053+
1054+
##### <a name="-bacula--director--console--password"></a>`password`
1055+
1056+
Data type: `String[1]`
1057+
1058+
The password that must be supplied for a named Bacula Console to be authorized
1059+
1060+
##### <a name="-bacula--director--console--jobacl"></a>`jobacl`
1061+
1062+
Data type: `Optional[String[1]]`
1063+
1064+
A list of Job resource names that can be accessed by the console.
1065+
1066+
Default value: `undef`
1067+
1068+
##### <a name="-bacula--director--console--clientacl"></a>`clientacl`
1069+
1070+
Data type: `Optional[String[1]]`
1071+
1072+
A list of Client resource names that can be accessed by the console.
1073+
1074+
Default value: `undef`
1075+
1076+
##### <a name="-bacula--director--console--storageacl"></a>`storageacl`
1077+
1078+
Data type: `Optional[String[1]]`
1079+
1080+
A list of Storage resource names that can be accessed by the console.
1081+
1082+
Default value: `undef`
1083+
1084+
##### <a name="-bacula--director--console--scheduleacl"></a>`scheduleacl`
1085+
1086+
Data type: `Optional[String[1]]`
1087+
1088+
A list of Schedule resource names that can be accessed by the console.
1089+
1090+
Default value: `undef`
1091+
1092+
##### <a name="-bacula--director--console--poolacl"></a>`poolacl`
1093+
1094+
Data type: `Optional[String[1]]`
1095+
1096+
A list of Pool resource names that can be accessed by the console.
1097+
1098+
Default value: `undef`
1099+
1100+
##### <a name="-bacula--director--console--filesetacl"></a>`filesetacl`
1101+
1102+
Data type: `Optional[String[1]]`
1103+
1104+
A list of FileSet resource names that can be accessed by the console.
1105+
1106+
Default value: `undef`
1107+
1108+
##### <a name="-bacula--director--console--catalogacl"></a>`catalogacl`
1109+
1110+
Data type: `String[1]`
1111+
1112+
A list of Catalog resource names that can be accessed by the console.
1113+
1114+
Default value: `'*all*'`
1115+
1116+
##### <a name="-bacula--director--console--commandacl"></a>`commandacl`
1117+
1118+
Data type:
1119+
1120+
```puppet
1121+
Array[Enum[
1122+
['add'], ['autodisplay'], ['automount'], ['cancel'], ['cloud'], ['create'], ['delete'], ['disable'], ['enable'], ['estimate'],
1123+
['exit'], ['gui'], ['help'], ['label'], ['list'], ['llist'], ['messages'], ['memory'], ['mount'], ['prune'], ['purge'], ['query'],
1124+
['quit'], ['relabel'], ['release'], ['reload'], ['restart'], ['resume'], ['restore'], ['run'], ['setbandwidth'], ['setdebug'],
1125+
['setip'], ['show'], ['sqlquery'], ['status'], ['tag'], ['time'], ['trace'], ['umount'], ['unmount'], ['update'], ['use'], ['var'],
1126+
['version'], ['wait'], ['.api'], ['.backups'], ['.clients'], ['.catalogs'], ['.defaults'], ['.die'], ['.dir'], ['.dump'], ['.exit'],
1127+
['.events'], ['.filesets'], ['.help'], ['.jobs'], ['.estimate'], ['.jlist'], ['.levels'], ['.messages'], ['.msgs'], ['.pools'],
1128+
['.quit'], ['.putfile'], ['.schedule'], ['.sql'], ['.status'], ['.storage'], ['.volstatus'], ['.media'], ['.mediatypes'],
1129+
['.locations'], ['.actiononpurge'], ['.bvfs_lsdirs'], ['.bvfs_lsfiles'], ['.bvfs_get_volumes'], ['.bvfs_update'],
1130+
['.bvfs_get_jobids'], ['.bvfs_get_jobs'], ['.bvfs_get_bootstrap'], ['.bvfs_get_fileindex'], ['.bvfs_versions'], ['.bvfs_get_delta'],
1131+
['.bvfs_restore'], ['.bvfs_cleanup'], ['.bvfs_decode_lstat'], ['.bvfs_clear_cache'], ['.bvfs_update_fv'], ['.bvfs_delete_fileid'],
1132+
['.setuid'], ['.ls'], ['.types'], ['.query'], ['.tags'],
1133+
]]
1134+
```
1135+
1136+
A list of of console commands that can be executed by the console.
1137+
1138+
Default value: `['list']`
1139+
1140+
##### <a name="-bacula--director--console--whereacl"></a>`whereacl`
1141+
1142+
Data type: `Optional[String[1]]`
1143+
1144+
This directive permits you to specify where a restricted console can restore files.
1145+
1146+
Default value: `undef`
1147+
10101148
### <a name="bacula--director--fileset"></a>`bacula::director::fileset`
10111149

10121150
This class handles a Director's fileset.conf entry. Filesets are intended to

manifests/director.pp

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -155,6 +155,7 @@
155155
]
156156

157157
$sub_confs_with_secrets = [
158+
"${conf_dir}/conf.d/console.conf",
158159
"${conf_dir}/conf.d/client.conf",
159160
"${conf_dir}/conf.d/storage.conf",
160161
]

manifests/director/console.pp

Lines changed: 70 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,70 @@
1+
# @summary Define a Bacula Director Console
2+
#
3+
# This define creates a console declaration for the director.
4+
# Resources of this type are intended to manage conf.d/console.conf entries.
5+
#
6+
# @param conf_dir The bacula configuration director. Should not need adjusting
7+
# @param password The password that must be supplied for a named Bacula Console to be authorized
8+
# @param jobacl A list of Job resource names that can be accessed by the console.
9+
# @param clientacl A list of Client resource names that can be accessed by the console.
10+
# @param storageacl A list of Storage resource names that can be accessed by the console.
11+
# @param scheduleacl A list of Schedule resource names that can be accessed by the console.
12+
# @param poolacl A list of Pool resource names that can be accessed by the console.
13+
# @param filesetacl A list of FileSet resource names that can be accessed by the console.
14+
# @param catalogacl A list of Catalog resource names that can be accessed by the console.
15+
# @param commandacl A list of of console commands that can be executed by the console.
16+
# @param whereacl This directive permits you to specify where a restricted console can restore files.
17+
#
18+
# Aside from Director resource names and console command names,
19+
# the special keyword *all* can be specified in any of the above access control lists.
20+
# When this keyword is present, any resource or command name (which ever is appropriate) will be accepted.
21+
#
22+
# @example
23+
# bacula::director::console { 'Monitoring':
24+
# password => 'monitoring_password',
25+
# }
26+
#
27+
define bacula::director::console (
28+
String[1] $password,
29+
String $conf_dir = $bacula::conf_dir,
30+
String[1] $catalogacl = '*all*',
31+
Array[Enum[
32+
['add'], ['autodisplay'], ['automount'], ['cancel'], ['cloud'], ['create'], ['delete'], ['disable'], ['enable'], ['estimate'],
33+
['exit'], ['gui'], ['help'], ['label'], ['list'], ['llist'], ['messages'], ['memory'], ['mount'], ['prune'], ['purge'], ['query'],
34+
['quit'], ['relabel'], ['release'], ['reload'], ['restart'], ['resume'], ['restore'], ['run'], ['setbandwidth'], ['setdebug'],
35+
['setip'], ['show'], ['sqlquery'], ['status'], ['tag'], ['time'], ['trace'], ['umount'], ['unmount'], ['update'], ['use'], ['var'],
36+
['version'], ['wait'], ['.api'], ['.backups'], ['.clients'], ['.catalogs'], ['.defaults'], ['.die'], ['.dir'], ['.dump'], ['.exit'],
37+
['.events'], ['.filesets'], ['.help'], ['.jobs'], ['.estimate'], ['.jlist'], ['.levels'], ['.messages'], ['.msgs'], ['.pools'],
38+
['.quit'], ['.putfile'], ['.schedule'], ['.sql'], ['.status'], ['.storage'], ['.volstatus'], ['.media'], ['.mediatypes'],
39+
['.locations'], ['.actiononpurge'], ['.bvfs_lsdirs'], ['.bvfs_lsfiles'], ['.bvfs_get_volumes'], ['.bvfs_update'],
40+
['.bvfs_get_jobids'], ['.bvfs_get_jobs'], ['.bvfs_get_bootstrap'], ['.bvfs_get_fileindex'], ['.bvfs_versions'], ['.bvfs_get_delta'],
41+
['.bvfs_restore'], ['.bvfs_cleanup'], ['.bvfs_decode_lstat'], ['.bvfs_clear_cache'], ['.bvfs_update_fv'], ['.bvfs_delete_fileid'],
42+
['.setuid'], ['.ls'], ['.types'], ['.query'], ['.tags'],
43+
]] $commandacl = ['list'],
44+
Optional[String[1]] $jobacl = undef,
45+
Optional[String[1]] $clientacl = undef,
46+
Optional[String[1]] $storageacl = undef,
47+
Optional[String[1]] $scheduleacl = undef,
48+
Optional[String[1]] $poolacl = undef,
49+
Optional[String[1]] $filesetacl = undef,
50+
Optional[String[1]] $whereacl = undef,
51+
) {
52+
$epp_console_variables = {
53+
name => $name,
54+
password => $password,
55+
commandacl => $commandacl,
56+
whereacl => $whereacl,
57+
jobacl => $jobacl,
58+
clientacl => $clientacl,
59+
storageacl => $scheduleacl,
60+
scheduleacl => $scheduleacl,
61+
poolacl => $poolacl,
62+
filesetacl => $filesetacl,
63+
catalogacl => $catalogacl,
64+
}
65+
66+
concat::fragment { "bacula-director-console-${name}":
67+
target => "${conf_dir}/conf.d/console.conf",
68+
content => epp('bacula/bacula-dir-console.epp', $epp_console_variables),
69+
}
70+
}

templates/bacula-dir-console.epp

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
<%
2+
|
3+
String $name,
4+
String $password,
5+
String $catalogacl,
6+
Array $commandacl,
7+
Optional[String] $jobacl,
8+
Optional[String] $clientacl,
9+
Optional[String] $storageacl,
10+
Optional[String] $scheduleacl,
11+
Optional[String] $poolacl,
12+
Optional[String] $filesetacl,
13+
Optional[String] $whereacl,
14+
|
15+
-%>
16+
Console {
17+
Name = <%= $name %>
18+
Password = "<%= $password %>"
19+
<% if $jobacl { -%>
20+
JobACL = <%= $jobacl %>
21+
<% } -%>
22+
<% if $clientacl { -%>
23+
ClientACL = <%= $clientacl %>
24+
<% } -%>
25+
<% if $storageacl { -%>
26+
StorageACL = <%= $storageacl %>
27+
<% } -%>
28+
<% if $scheduleacl { -%>
29+
ScheduleACL = <%= $scheduleacl %>
30+
<% } -%>
31+
<% if $poolacl { -%>
32+
PoolACL = <%= $poolacl %>
33+
<% } -%>
34+
<% if $filesetacl { -%>
35+
FileSetACL = <%= $filesetacl %>
36+
<% } -%>
37+
CatalogACL = <%= $catalogacl %>
38+
CommandACL = <%= $commandacl.join(', ') %>
39+
<% if $whereacl { -%>
40+
WhereACL = <%= $whereacl %>
41+
<% } -%>
42+
}

templates/bacula-dir-tail.epp

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@
55
@<%= $bacula::conf_dir %>/conf.d/fileset.conf
66
@<%= $bacula::conf_dir %>/conf.d/jobdefs.conf
77
@<%= $bacula::conf_dir %>/conf.d/job.conf
8+
@<%= $bacula::conf_dir %>/conf.d/console.conf

0 commit comments

Comments
 (0)