diff --git a/manifests/config.pp b/manifests/config.pp index 66e9d77..f93119f 100644 --- a/manifests/config.pp +++ b/manifests/config.pp @@ -5,6 +5,12 @@ $agent_ocs_pause = $::ocsinventory::agent_ocs_pause, $agent_ocs_server = $::ocsinventory::agent_ocs_server, $agent_ocs_tag = $::ocsinventory::agent_ocs_tag, + $db_host = $::ocsinventory::db_host, + $db_port = $::ocsinventory::db_port, + $db_name = $::ocsinventory::db_name, + $db_local = $::ocsinventory::db_local, + $db_user = $::ocsinventory::db_user, + $db_pass = $::ocsinventory::db_pass, ) { File { group => $::ocsinventory::config_group, @@ -72,6 +78,19 @@ ensure => file, content => template("ocsinventory/server.${::osfamily}.conf.erb"); } + if $::osfamily == 'Debian' { + file { "${::ocsinventory::params::deploy_reports_dir}/dbconfig.inc.php": + ensure => file, + content => template('ocsinventory/reports.Debian.dbconfig.inc.php.erb'), + owner => $::ocsinventory::config_httpd_user, + group => $::ocsinventory::config_httpd_group, + } + exec { "rm install.php": + command => "rm ${::ocsinventory::params::deploy_reports_dir}/install.php", + onlyif => ["test -f ${::ocsinventory::params::deploy_reports_dir}/install.php", + "mysql -u $db_user -p$db_pass -h $db_host -P $db_port $db_name -e 'show tables' | grep -q config"] + } + } } } diff --git a/manifests/init.pp b/manifests/init.pp index 8786da9..284a473 100644 --- a/manifests/init.pp +++ b/manifests/init.pp @@ -80,6 +80,14 @@ $pkg_list_server = $::ocsinventory::params::pkg_list_server, $pkg_server_ensure = $::ocsinventory::params::pkg_server_ensure, $server = $::ocsinventory::params::server, + $db_host = $::ocsinventory::params::db_host, + $db_port = $::ocsinventory::params::db_port, + $db_name = $::ocsinventory::params::db_name, + $db_local = $::ocsinventory::params::db_local, + $db_user = $::ocsinventory::params::db_user, + $db_pass = $::ocsinventory::params::db_passs, + $config_httpd_user = $::ocsinventory::params::httpd_user, + $config_httpd_group = $::ocsinventory::params::httpd_group, ) inherits ::ocsinventory::params { class { '::ocsinventory::install': } -> class { '::ocsinventory::config': } -> diff --git a/manifests/params.pp b/manifests/params.pp index b276d5d..30f1df9 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -9,6 +9,12 @@ $pkg_agent_ensure = present $pkg_server_ensure = present $server = false + $db_host = 'localhost' + $db_port = 3306 + $db_name = 'ocsweb' + $db_local = 'ocsweb' + $db_user = 'ocs' + $db_passs = 'ocs' case $::osfamily { 'RedHat': { @@ -21,7 +27,6 @@ $log_dir_agent = '/var/log/ocsinventory-agent' $log_dir_server = '/var/log/ocsinventory-server' $pkg_deps = undef - case $::lsbmajdistrelease { '7': { $pkg_list_agent = [ @@ -49,7 +54,28 @@ 'ocsinventory-server', ] } + 'Debian': { + $config_dir = '/etc/ocsinventory' + $config_dir_mode = '0755' + $config_dir_recurse = false + $config_file_mode = '0644' + $config_group = 'root' + $config_user = 'root' + $log_dir_agent = '/var/log/ocsinventory-agent' + $log_dir_server = '/var/log/ocsinventory-server' + $pkg_deps = undef + $httpd_user = 'www-data' + $httpd_group = 'www-data' + $pkg_list_agent = [ + 'ocsinventory-agent', + ] + $pkg_list_server = [ + 'ocsinventory-reports', + 'ocsinventory-server', + ] + $deploy_reports_dir = '/usr/share/ocsinventory-reports' + } default: { fail "Operating system ${::operatingsystem} is not supported." } diff --git a/templates/reports.Debian.conf.erb b/templates/reports.Debian.conf.erb new file mode 100644 index 0000000..61eed14 --- /dev/null +++ b/templates/reports.Debian.conf.erb @@ -0,0 +1,68 @@ +################################################################################ +# +# OCS Inventory NG Administration Server +# +# Copyleft 2008 OCS Inventory NG Team +# Web: http://www.ocsinventory-ng.org +# +# This code is open source and may be copied and modified as long as the source +# code is always made freely available. +# Please refer to the General Public Licence http://www.gnu.org/ or Licence.txt +################################################################################ + +# +# ANY CHANGE ON THIS FILE REQUIRES APACHE RESTART TO TAKE EFFECT +# + +################################################################################ +# Administration console public pages +# + +# Uncomment if you want a virtual host for OCS Inventory NG +# +# ServerName ocsinventory-ng +# ServerAlias ocsinventory-ng.yourdomain.tld +# DocumentRoot /usr/share/ocsinventory-reports + +Alias /ocsreports /usr/share/ocsinventory-reports + + + # By default, users can use console from everywhere + + Require all granted + + + Order deny,allow + Allow from all + + + Options Indexes FollowSymLinks + DirectoryIndex index.php + + # Uncomment following to force use of HTTPS in Administration Server + #SSLRequireSSL + + #php_flag short_open_tag on + php_flag file_uploads on + + # Some PHP tuning for deployement feature up to 50 MB + php_value post_max_size 51M + php_value upload_max_filesize 50M + + # You may have to uncomment following on errors + #php_value memory_limit 16M + #php_value max_execution_time -1 + #php_value max_input_time -1 + + # Uncomment following to allow HTTP body request up to 4 MB + # instead default 512 KB + #LimitRequestBody 4194304 + + +################################################################################ +# Deployment packages download area +# +Alias /download /var/lib/ocsinventory-reports/download + +# + diff --git a/templates/reports.Debian.dbconfig.inc.php.erb b/templates/reports.Debian.dbconfig.inc.php.erb new file mode 100644 index 0000000..1e8b369 --- /dev/null +++ b/templates/reports.Debian.dbconfig.inc.php.erb @@ -0,0 +1,7 @@ +"); +define("SERVER_READ","<%= @db_host %>"); +define("SERVER_WRITE","<%= @db_host %>"); +define("COMPTE_BASE","<%= @db_user %>"); +define("PSWD_BASE","<%= @db_pass %>"); +?> \ No newline at end of file diff --git a/templates/server.Debian.conf.erb b/templates/server.Debian.conf.erb new file mode 100644 index 0000000..a830d5a --- /dev/null +++ b/templates/server.Debian.conf.erb @@ -0,0 +1,336 @@ +################################################################################ +# +# OCS Inventory NG Communication Server Perl Module Setup +# +# Copyleft 2006 Pascal DANEK +# Web: http://www.ocsinventory-ng.org +# +# This code is open source and may be copied and modified as long as the source +# code is always made freely available. +# Please refer to the General Public Licence http://www.gnu.org/ or Licence.txt +################################################################################ + + # Which version of mod_perl we are using + # For mod_perl <= 1.999_21, replace 2 by 1 + # For mod_perl > 1.999_21, replace 2 by 2 + PerlSetEnv OCS_MODPERL_VERSION 2 + + # Master Database settings + # Replace localhost by hostname or ip of MySQL server for WRITE + PerlSetEnv OCS_DB_HOST <%= @db_host %> + # Replace 3306 by port where running MySQL server, generally 3306 + PerlSetEnv OCS_DB_PORT <%= @db_port %> + # Name of database + PerlSetEnv OCS_DB_NAME <%= @db_name %> + PerlSetEnv OCS_DB_LOCAL <%= @db_local %> + # User allowed to connect to database + PerlSetEnv OCS_DB_USER <%= @db_user %> + # Password for user + PerlSetVar OCS_DB_PWD <%= @db_pass %> + + # Slave Database settings + # Replace localhost by hostname or ip of MySQL server for READ + # Useful if you handle mysql slave databases + # PerlSetEnv OCS_DB_SL_HOST localhost + # Replace 3306 by port where running MySQL server, generally 3306 + # PerlSetEnv OCS_DB_SL_PORT_SLAVE 3306 + # User allowed to connect to database + # PerlSetEnv OCS_DB_SL_USER ocs + # Name of the database + # PerlSetEnv OCS_DB_SL_NAME ocsweb + # Password for user + # PerlSetVar OCS_DB_SL_PWD ocs + + # Path to log directory (must be writeable) + PerlSetEnv OCS_OPT_LOGPATH "/var/log/ocsinventory-server" + + # If you need to specify a mysql socket that the client's built-in + #PerlSetEnv OCS_OPT_DBI_MYSQL_SOCKET "path/to/mysql/unix/socket" + # DBI verbosity + PerlSetEnv OCS_OPT_DBI_PRINT_ERROR 0 + + # Unicode support + PerlSetEnv OCS_OPT_UNICODE_SUPPORT 1 + + # If you are using a multi server architecture, + # Put the ip addresses of the slaves on the master + # (This is read as perl regular expressions) + PerlAddVar OCS_OPT_TRUSTED_IP 127.0.0.1 + #PerlAddVar OCS_OPT_TRUSTED_IP XXX.XXX.XXX.XXX + +# ===== WEB SERVICE (SOAP) SETTINGS ===== + + PerlSetEnv OCS_OPT_WEB_SERVICE_ENABLED 0 + PerlSetEnv OCS_OPT_WEB_SERVICE_RESULTS_LIMIT 100 + # PerlSetEnv OCS_OPT_WEB_SERVICE_PRIV_MODS_CONF "WEBSERV_PRIV_MOD_CONF_FILE" + +# Be careful: you must restart apache to make settings taking effects + + # Configure engine to use the settings from this file + PerlSetEnv OCS_OPT_OPTIONS_NOT_OVERLOADED 0 + + # Try to use other compress algorythm than raw zlib + # GUNZIP and clear XML are supported + PerlSetEnv OCS_OPT_COMPRESS_TRY_OTHERS 1 + +############################################################## +# ===== OPTIONS BELOW ARE OVERLOADED IF YOU USE OCS GUI =====# +############################################################## + +# NOTE: IF YOU WANT TO USE THIS CONFIG FILE INSTEAD, set OCS_OPT_OPTIONS_NOT_OVERLOADED to '1' + +# ===== MAIN SETTINGS ===== + + # Enable engine logs (see LOGPATH setting) + PerlSetEnv OCS_OPT_LOGLEVEL 0 + # Specify agent's prolog frequency + PerlSetEnv OCS_OPT_PROLOG_FREQ 12 + # Configure the duplicates detection system + PerlSetEnv OCS_OPT_AUTO_DUPLICATE_LVL 15 + # Futur security improvements + PerlSetEnv OCS_OPT_SECURITY_LEVEL 0 + # Validity of a computer's lock + PerlSetEnv OCS_OPT_LOCK_REUSE_TIME 600 + # Enable the history tracking system (useful for external data synchronisation + PerlSetEnv OCS_OPT_TRACE_DELETED 0 + +# ===== INVENTORY SETTINGS ===== + + # Specify the validity of inventory data + PerlSetEnv OCS_OPT_FREQUENCY 0 + # Configure engine to update inventory regarding to CHECKSUM agent value (lower DB backend load) + PerlSetEnv OCS_OPT_INVENTORY_DIFF 1 + # Make engine consider an inventory as a transaction (lower concurency, better disk usage) + PerlSetEnv OCS_OPT_INVENTORY_TRANSACTION 1 + # Configure engine to make a differential update of inventory sections (row level). Lower DB backend load, higher frontend load + PerlSetEnv OCS_OPT_INVENTORY_WRITE_DIFF 1 + # Enable some stuff to improve DB queries, especially for GUI multicriteria searching system + PerlSetEnv OCS_OPT_INVENTORY_CACHE_ENABLED 1 + # Specify when the engine will clean the inventory cache structures + PerlSetEnv OCS_OPT_INVENTORY_CACHE_REVALIDATE 7 + # Enable you to keep trace of every elements encountered in db life + PerlSetEnv OCS_OPT_INVENTORY_CACHE_KEEP 1 + +# ===== SOFTWARES DEPLOYMENT SETTINGS ===== + + # Enable this feature + PerlSetEnv OCS_OPT_DOWNLOAD 0 + # Package wich have a priority superior than this value will not be downloaded + PerlSetEnv OCS_OPT_DOWNLOAD_PERIOD_LENGTH 10 + # Time between two download cycles (bandwidth control) + PerlSetEnv OCS_OPT_DOWNLOAD_CYCLE_LATENCY 60 + # Time between two fragment downloads (bandwidth control) + PerlSetEnv OCS_OPT_DOWNLOAD_FRAG_LATENCY 60 + # Specify if you want to track packages affected to a group on computer's level + PerlSetEnv OCS_OPT_DOWNLOAD_GROUPS_TRACE_EVENTS 1 + # Time between two download periods (bandwidth control) + PerlSetEnv OCS_OPT_DOWNLOAD_PERIOD_LATENCY 60 + # Agents will send ERR_TIMEOUT event and clean the package it is older than this setting + PerlSetEnv OCS_OPT_DOWNLOAD_TIMEOUT 7 + # Agents will send an error event and clean the package if package command does not respond during this setting + PerlSetEnv OCS_OPT_DOWNLOAD_EXECUTION_TIMEOUT 120 + + # Enable ocs engine to deliver agent's files (deprecated) + PerlSetEnv OCS_OPT_DEPLOY 0 + # Enable the softwares deployment capacity (bandwidth control) + +# ===== GROUPS SETTINGS ===== + + # Enable the computer\s groups feature + PerlSetEnv OCS_OPT_ENABLE_GROUPS 1 + # Random number computed in the defined range. Designed to avoid computing many groups in the same process + PerlSetEnv OCS_OPT_GROUPS_CACHE_OFFSET 43200 + # Specify the validity of computer's groups (default: compute it once a day - see offset) + PerlSetEnv OCS_OPT_GROUPS_CACHE_REVALIDATE 43200 + +# ===== IPDISCOVER SETTINGS ===== + + # Specify how much agent per LAN will discovered connected peripherals (0 to disable) + PerlSetEnv OCS_OPT_IPDISCOVER 2 + # Specify the minimal difference to replace an ipdiscover agent + PerlSetEnv OCS_OPT_IPDISCOVER_BETTER_THRESHOLD 1 + # Time between 2 arp requests (mini: 10 ms) + PerlSetEnv OCS_OPT_IPDISCOVER_LATENCY 100 + # Specify when to remove a computer when it has not come until this period + PerlSetEnv OCS_OPT_IPDISCOVER_MAX_ALIVE 14 + # Disable the time before a first election (not recommended) + PerlSetEnv OCS_OPT_IPDISCOVER_NO_POSTPONE 0 + # Enable groups for ipdiscover (for example, you might want to prevent some groups to be ipdiscover agents) + PerlSetEnv OCS_OPT_IPDISCOVER_USE_GROUPS 1 + +# ===== INVENTORY FILES MAPPING SETTINGS ===== + + # Use with ocsinventory-injector, enable the multi entities feature + PerlSetEnv OCS_OPT_GENERATE_OCS_FILES 0 + # Generate either compressed file or clear XML text + PerlSetEnv OCS_OPT_OCS_FILES_FORMAT OCS + # Specify if you want to keep trace of all inventory between to synchronisation with the higher level server + PerlSetEnv OCS_OPT_OCS_FILES_OVERWRITE 0 + # Path to ocs files directory (must be writeable) + PerlSetEnv OCS_OPT_OCS_FILES_PATH /tmp + +# ===== FILTER SETTINGS ===== + + # Enable prolog filter stack + PerlSetEnv OCS_OPT_PROLOG_FILTER_ON 0 + # Enable core filter system to modify some things "on the fly" + PerlSetEnv OCS_OPT_INVENTORY_FILTER_ENABLED 0 + # Enable inventory flooding filter. A dedicated ipaddress ia allowed to send a new computer only once in this period + PerlSetEnv OCS_OPT_INVENTORY_FILTER_FLOOD_IP 0 + # Period definition for INVENTORY_FILTER_FLOOD_IP + PerlSetEnv OCS_OPT_INVENTORY_FILTER_FLOOD_IP_CACHE_TIME 300 + # Enable inventory filter stack + PerlSetEnv OCS_OPT_INVENTORY_FILTER_ON 0 + +# ===== DATA FILTER ===== + + #Enable the dat filtering capacity + PerlSetEnv OCS_OPT_DATA_FILTER 0 + + # Set the table names and the field associated you want to filter + #PerlAddVar OCS_OPT_DATA_TO_FILTER HARDWARE + #PerlAddVar OCS_OPT_DATA_TO_FILTER USERID + + +# ===== REGISTRY SETTINGS ===== + + # Enable the registry capacity + PerlSetEnv OCS_OPT_REGISTRY 1 + +# ===== SNMP SETTINGS ===== + + # Enable the SNMP capacity + PerlSetEnv OCS_OPT_SNMP 0 + + # Configure engine to update snmp inventory regarding to snmp_laststate table (lower DB backend load) + PerlSetEnv OCS_OPT_SNMP_INVENTORY_DIFF 1 + +# ===== SESSION SETTINGS ===== +# Not yet in GUI + + # Validity of a session (prolog=>postinventory) + PerlSetEnv OCS_OPT_SESSION_VALIDITY_TIME 600 + # Consider a session obsolete if it is older thant this value + PerlSetEnv OCS_OPT_SESSION_CLEAN_TIME 86400 + # Accept an inventory only if required by server + #( Refuse "forced" inventory) + PerlSetEnv OCS_OPT_INVENTORY_SESSION_ONLY 0 + +# ===== TAG ===== + + # The default behavior of the server is to ignore TAG changes from the + # agent. + PerlSetEnv OCS_OPT_ACCEPT_TAG_UPDATE_FROM_CLIENT 0 + +# ===== EXTERNAL USERAGENTS ===== + + #Path for external useragents reference file + #!! WARNING !! : external agents may not be supported by OCS NG Community ! + #PerlSetEnv OCS_OPT_EXT_USERAGENTS_FILE_PATH /tmp/yourfile.txt + +# ===== PLUGINS ===== + + PerlSetEnv OCS_PLUGINS_PERL_DIR "/etc/ocsinventory/ocsinventory-server/perl" + PerlSetEnv OCS_PLUGINS_CONF_DIR "/etc/ocsinventory/ocsinventory-server/plugins" + +# ===== DEPRECATED ===== + + # Set the proxy cache validity in http headers when sending a file + PerlSetEnv OCS_OPT_PROXY_REVALIDATE_DELAY 3600 + # Deprecated + PerlSetEnv OCS_OPT_UPDATE 0 + +############ DO NOT MODIFY BELOW ! ####################### + + # External modules + PerlModule Apache::DBI + PerlModule Compress::Zlib + PerlModule XML::Simple + + # Ocs plugins + #PerlModule Apache::Ocsinventory::Plugins + + # Ocs + PerlModule Apache::Ocsinventory + PerlModule Apache::Ocsinventory::Server::Constants + PerlModule Apache::Ocsinventory::Server::System + PerlModule Apache::Ocsinventory::Server::Communication + PerlModule Apache::Ocsinventory::Server::Inventory + PerlModule Apache::Ocsinventory::Server::Duplicate + + # Capacities + PerlModule Apache::Ocsinventory::Server::Capacities::Registry + PerlModule Apache::Ocsinventory::Server::Capacities::Update + PerlModule Apache::Ocsinventory::Server::Capacities::Ipdiscover + PerlModule Apache::Ocsinventory::Server::Capacities::Download + PerlModule Apache::Ocsinventory::Server::Capacities::Notify + PerlModule Apache::Ocsinventory::Server::Capacities::Snmp + # This module guides you through the module creation + # PerlModule Apache::Ocsinventory::Server::Capacities::Example + # This module adds some rules to filter some request sent to ocs server in the prolog and inventory stages + # PerlModule Apache::Ocsinventory::Server::Capacities::Filter + # This module add availibity to filter data from HARDWARE section (data filtered won't be stored in database) + # PerlModule Apache::Ocsinventory::Server::Capacities::Datafilter + + # PerlTaintCheck On + + # SSL apache settings + #SSLEngine "SSL_ENABLE" + #SSLCertificateFile "SSL_CERTIFICATE_FILE" + #SSLCertificateKeyFile "SSL_CERTIFICATE_KEY_FILE" + #SSLCACertificateFile "SSL_CERTIFICATE_FILE" + #SSLCACertificatePath "SSL_CERTIFICATE_PATH" + #SSLVerifyClient "SSL_VALIDATE_CLIENT" + + # Engine apache settings + # "Virtual" directory for handling OCS Inventory NG agents communications + # Be careful, do not create such directory into your web server root document ! + + # If you protect this area you have to deal with http_auth_* agent's parameters + # AuthType Basic + # AuthName "OCS Inventory agent area" + # AuthUserFile "/etc/ocsinventory/ocsinventory-server/htpasswd" + + + + Require all granted + # Require valid-user + + + + Order deny,allow + Allow from all + # Require valid-user + + + + SetHandler perl-script + PerlHandler Apache::Ocsinventory + + + # Web service apache settings + PerlModule Apache::Ocsinventory::SOAP + + + SetHandler perl-script + PerlHandler "Apache::Ocsinventory::SOAP" + +# AuthType Basic +# AuthName "OCS Inventory SOAP Area" +# # Use htpasswd to create/update soap-user (or another granted user) +# AuthUserFile "/etc/ocsinventory/ocsinventory-server/htpasswd" + + # By default, you can query web service from everywhere with a valid user + + + Require all granted + Require valid-user + + + + Order deny,allow + Allow from all + Require valid-user + + +