Puppet Class: nsd

Inherits:
::nsd::params
Defined in:
manifests/init.pp

Overview

Installs and configures NSD.

Examples:

Configure NSD with a single zone

include ::nsd

::nsd::zone { 'example.com.':
  source => 'puppet:///modules/example/example.com.zone',
}

Update the above example to allow zone transfers from other machines on the same network protected with the given TSIG key

include ::nsd

::nsd::key { 'example.':
  algorithm => 'hmac-sha256',
  secret    => '6z+8iKRIQrwN43TFfO/Rf2NHzpHIFVi6PsJ7dDESclc=',
}

::nsd::zone { 'example.com.':
  source      => 'puppet:///modules/example/example.com.zone',
  provide_xfr => [
    [$::network, $::netmask, 'example.'],
    ["${::network6}/64", 'example.'],
  ],
}

Configure NSD listening on the primary interface only as a slave for a single zone protected with the given TSIG key

class { '::nsd':
  ip_address => [
    $::ipaddress,
    $::ipaddress6,
  ],
}

::nsd::key { 'example.':
  algorithm => 'hmac-sha256',
  secret    => '6z+8iKRIQrwN43TFfO/Rf2NHzpHIFVi6PsJ7dDESclc=',
}

::nsd::zone { 'example.com.':
  allow_notify => [
    ['192.0.2.1', 'example.'],
  ],
  request_xfr  => [
    ['AXFR', '192.0.2.1', 'example.'],
  ],
}

Update NSD to slave more than one zone and make use of a pattern to simplify the configuration

class { '::nsd':
  ip_address => [
    $::ipaddress,
    $::ipaddress6,
  ],
}

::nsd::key { 'example.':
  algorithm => 'hmac-sha256',
  secret    => '6z+8iKRIQrwN43TFfO/Rf2NHzpHIFVi6PsJ7dDESclc=',
}

::nsd::pattern { 'example':
  allow_notify => [
    ['192.0.2.1', 'example.'],
  ],
  request_xfr  => [
    ['AXFR', '192.0.2.1', 'example.'],
  ],
}

::nsd::zone { 'example.com.':
  include_pattern => 'example',
}

::nsd::zone { 'example.org.':
  include_pattern => 'example',
}

Parameters:

  • conf_dir (Stdlib::Absolutepath) (defaults to: $::nsd::params::conf_dir)
  • group (String) (defaults to: $::nsd::params::group)
  • manage_control (Boolean) (defaults to: $::nsd::params::manage_control)
  • manage_package (Boolean) (defaults to: $::nsd::params::manage_package)
  • package_name (Optional[String]) (defaults to: $::nsd::params::package_name)
  • service_name (String) (defaults to: $::nsd::params::service_name)
  • chroot (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • control_cert_file (Optional[Stdlib::Absolutepath]) (defaults to: $::nsd::params::control_cert_file)
  • control_enable (Optional[Boolean]) (defaults to: $::nsd::params::control_enable)
  • control_interface (Optional[Array[IP::Address::NoSubnet, 1]]) (defaults to: undef)
  • control_key_file (Optional[Stdlib::Absolutepath]) (defaults to: $::nsd::params::control_key_file)
  • control_port (Optional[Bodgitlib::Port]) (defaults to: undef)
  • database (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • do_ip4 (Optional[Boolean]) (defaults to: undef)
  • do_ip6 (Optional[Boolean]) (defaults to: undef)
  • hide_version (Optional[Boolean]) (defaults to: undef)
  • identity (Optional[String]) (defaults to: undef)
  • ip_address (Optional[Array[NSD::Interface, 1]]) (defaults to: undef)
  • ip_transparent (Optional[Boolean]) (defaults to: undef)
  • ipv4_edns_size (Optional[Integer[0]]) (defaults to: undef)
  • ipv6_edns_size (Optional[Integer[0]]) (defaults to: undef)
  • log_time_ascii (Optional[Boolean]) (defaults to: undef)
  • logfile (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • minimal_responses (Optional[Boolean]) (defaults to: undef)
  • nsid (Optional[String]) (defaults to: undef)
  • outgoing_tcp_mss (Optional[Integer[0]]) (defaults to: undef)
  • pidfile (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • port (Optional[Bodgitlib::Port]) (defaults to: undef)
  • reuseport (Optional[Boolean]) (defaults to: undef)
  • round_robin (Optional[Boolean]) (defaults to: undef)
  • rrl_ipv4_prefix_length (Optional[Integer[0, 32]]) (defaults to: undef)
  • rrl_ipv6_prefix_length (Optional[Integer[0, 128]]) (defaults to: undef)
  • rrl_ratelimit (Optional[Integer[0]]) (defaults to: undef)
  • rrl_size (Optional[Integer[0]]) (defaults to: undef)
  • rrl_slip (Optional[Integer[0]]) (defaults to: undef)
  • rrl_whitelist_ratelimit (Optional[Integer[0]]) (defaults to: undef)
  • server_cert_file (Optional[Stdlib::Absolutepath]) (defaults to: $::nsd::params::server_cert_file)
  • server_count (Optional[Integer[1]]) (defaults to: undef)
  • server_key_file (Optional[Stdlib::Absolutepath]) (defaults to: $::nsd::params::server_key_file)
  • statistics (Optional[Integer[0]]) (defaults to: undef)
  • tcp_count (Optional[Integer[0]]) (defaults to: undef)
  • tcp_mss (Optional[Integer[0]]) (defaults to: undef)
  • tcp_query_count (Optional[Integer[0]]) (defaults to: undef)
  • tcp_timeout (Optional[Integer[0]]) (defaults to: undef)
  • username (Optional[String]) (defaults to: $::nsd::params::username)
  • verbosity (Optional[Integer[0, 3]]) (defaults to: undef)
  • version (Optional[String]) (defaults to: undef)
  • xfrd_reload_timeout (Optional[Integer[-1]]) (defaults to: undef)
  • xfrdfile (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • xfrdir (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • zonefiles_check (Optional[Boolean]) (defaults to: undef)
  • zonefiles_write (Optional[Integer[0]]) (defaults to: undef)
  • zonelistfile (Optional[Stdlib::Absolutepath]) (defaults to: undef)
  • zonesdir (Optional[Stdlib::Absolutepath]) (defaults to: $::nsd::params::zonesdir)

See Also:



136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
# File 'manifests/init.pp', line 136

class nsd (
  Stdlib::Absolutepath                      $conf_dir                = $::nsd::params::conf_dir,
  String                                    $group                   = $::nsd::params::group,
  Boolean                                   $manage_control          = $::nsd::params::manage_control,
  Boolean                                   $manage_package          = $::nsd::params::manage_package,
  Optional[String]                          $package_name            = $::nsd::params::package_name,
  String                                    $service_name            = $::nsd::params::service_name,
  # Below map to global configuration parameters
  Optional[Stdlib::Absolutepath]            $chroot                  = undef,
  Optional[Stdlib::Absolutepath]            $control_cert_file       = $::nsd::params::control_cert_file,
  Optional[Boolean]                         $control_enable          = $::nsd::params::control_enable,
  Optional[Array[IP::Address::NoSubnet, 1]] $control_interface       = undef,
  Optional[Stdlib::Absolutepath]            $control_key_file        = $::nsd::params::control_key_file,
  Optional[Bodgitlib::Port]                 $control_port            = undef,
  Optional[Stdlib::Absolutepath]            $database                = undef,
  Optional[Boolean]                         $do_ip4                  = undef,
  Optional[Boolean]                         $do_ip6                  = undef,
  Optional[Boolean]                         $hide_version            = undef,
  Optional[String]                          $identity                = undef,
  Optional[Array[NSD::Interface, 1]]        $ip_address              = undef,
  Optional[Boolean]                         $ip_transparent          = undef,
  Optional[Integer[0]]                      $ipv4_edns_size          = undef,
  Optional[Integer[0]]                      $ipv6_edns_size          = undef,
  Optional[Boolean]                         $log_time_ascii          = undef,
  Optional[Stdlib::Absolutepath]            $logfile                 = undef,
  Optional[Boolean]                         $minimal_responses       = undef,
  Optional[String]                          $nsid                    = undef,
  Optional[Integer[0]]                      $outgoing_tcp_mss        = undef,
  Optional[Stdlib::Absolutepath]            $pidfile                 = undef,
  Optional[Bodgitlib::Port]                 $port                    = undef,
  Optional[Boolean]                         $reuseport               = undef,
  Optional[Boolean]                         $round_robin             = undef,
  Optional[Integer[0, 32]]                  $rrl_ipv4_prefix_length  = undef,
  Optional[Integer[0, 128]]                 $rrl_ipv6_prefix_length  = undef,
  Optional[Integer[0]]                      $rrl_ratelimit           = undef,
  Optional[Integer[0]]                      $rrl_size                = undef,
  Optional[Integer[0]]                      $rrl_slip                = undef,
  Optional[Integer[0]]                      $rrl_whitelist_ratelimit = undef,
  Optional[Stdlib::Absolutepath]            $server_cert_file        = $::nsd::params::server_cert_file,
  Optional[Integer[1]]                      $server_count            = undef,
  Optional[Stdlib::Absolutepath]            $server_key_file         = $::nsd::params::server_key_file,
  Optional[Integer[0]]                      $statistics              = undef,
  Optional[Integer[0]]                      $tcp_count               = undef,
  Optional[Integer[0]]                      $tcp_mss                 = undef,
  Optional[Integer[0]]                      $tcp_query_count         = undef,
  Optional[Integer[0]]                      $tcp_timeout             = undef,
  Optional[String]                          $username                = $::nsd::params::username,
  Optional[Integer[0, 3]]                   $verbosity               = undef,
  Optional[String]                          $version                 = undef,
  Optional[Integer[-1]]                     $xfrd_reload_timeout     = undef,
  Optional[Stdlib::Absolutepath]            $xfrdfile                = undef,
  Optional[Stdlib::Absolutepath]            $xfrdir                  = undef,
  Optional[Boolean]                         $zonefiles_check         = undef,
  Optional[Integer[0]]                      $zonefiles_write         = undef,
  Optional[Stdlib::Absolutepath]            $zonelistfile            = undef,
  Optional[Stdlib::Absolutepath]            $zonesdir                = $::nsd::params::zonesdir,
) inherits ::nsd::params {

  if $manage_control and ($control_cert_file != $::nsd::params::control_cert_file or $control_key_file != $::nsd::params::control_key_file or $server_cert_file != $::nsd::params::server_cert_file or $server_key_file != $::nsd::params::server_key_file) {
    fail('Cannot have $manage_control enabled with non-standard locations for remote control keys and/or certificates')
  }

  contain ::nsd::install
  contain ::nsd::config
  contain ::nsd::service

  Class['::nsd::install'] ~> Class['::nsd::config'] ~> Class['::nsd::service']
}