]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/dns/recipes/default.rb
Generate a DNS include file for SSHFP records
[chef.git] / cookbooks / dns / recipes / default.rb
index 1896e99b82e99d0049e2ad6d8a2384f2111f222a..6bf913cb3745cb894431ffefe3855752cffc0a38 100644 (file)
@@ -36,6 +36,14 @@ package %w[
   libjson-xs-perl
 ]
 
+# remote_file "/usr/local/bin/dnscontrol" do
+#   action :create
+#   source "https://github.com/StackExchange/dnscontrol/releases/download/v2.10.0/dnscontrol-Linux"
+#   owner "root"
+#   group "root"
+#   mode 0o755
+# end
+
 directory "/srv/dns.openstreetmap.org" do
   owner "root"
   group "root"
@@ -95,6 +103,13 @@ template "/usr/local/bin/dns-update" do
   variables :passwords => passwords, :geoservers => geoservers
 end
 
+cookbook_file "/usr/local/bin/dns-update-sshfp" do
+  source "dns-update-sshfp"
+  owner "git"
+  group "git"
+  mode 0o750
+end
+
 execute "dns-update" do
   action :nothing
   command "/usr/local/bin/dns-update"
@@ -109,6 +124,22 @@ directory "/var/lib/dns" do
   notifies :run, "execute[dns-update]"
 end
 
+template "/var/lib/dns/creds.json" do
+  source "creds.json.erb"
+  owner "git"
+  group "git"
+  mode 0o440
+  variables :passwords => passwords
+end
+
+execute "dns-update-sshfp" do
+  action :nothing
+  command "/usr/local/bin/dns-update-sshfp"
+  user "git"
+  group "git"
+  subscribes :run, "template[/etc/ssh/ssh_known_hosts]"
+end
+
 cookbook_file "#{node[:dns][:repository]}/hooks/post-receive" do
   source "post-receive"
   owner "git"