munin-master: Force TLS when connecting to nodes

This commit is contained in:
Timo Makinen 2021-03-18 16:55:34 +00:00
parent 15fec6b391
commit 5d83306491
2 changed files with 19 additions and 0 deletions

View file

@ -12,6 +12,12 @@
owner: munin
group: apache
- name: add munin to hostkey group
user:
name: munin
groups: hostkey
append: yes
- name: create apache config
copy:
dest: /etc/httpd/conf.local.d/munin.conf
@ -21,6 +27,14 @@
group: "{{ ansible_wheel }}"
notify: restart apache
- name: create tls config
template:
dest: /etc/munin/conf.d/00-tls.conf
src: tls.conf.j2
mode: 0644
owner: root
group: "{{ ansible_wheel }}"
- name: remove localhost node
file:
path: /etc/munin/conf.d/local.conf

View file

@ -0,0 +1,5 @@
tls paranoid
tls_verify_certificate yes
tls_private_key {{ tls_private }}/{{ inventory_hostname }}.key
tls_certificate {{ tls_certs }}/{{ inventory_hostname }}.crt
tls_ca_certificate {{ tls_certs }}/ca.crt