tyska

Untitled

Jan 20th, 2012
167
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.71 KB | None | 0 0
  1. Error message:
  2.  
  3. info: Caching catalog for 10.0.0.205
  4. info: Applying configuration version '1327058802'
  5. err: /Stage[main]//Node[10.0.0.205]/File[/home/ubuntu/teste]: Could not evaluate: Error 400 on SERVER: Not authorized to call find on /file_metadata/files/teste Could not retrieve file metadata for puppet:///files/teste: Error 400 on SERVER: Not authorized to call find on /file_metadata/files/teste at /etc/puppet/manifests/site.pp:24
  6. notice: Finished catalog run in 0.08 seconds
  7.  
  8.  
  9. -----
  10.  
  11. site.pp
  12.  
  13. node '10.0.0.205'{
  14. file {"/home/ubuntu/teste":
  15. source => 'puppet:///files/teste'
  16. }
  17. }
  18.  
  19. ---------
  20.  
  21. auth.conf
  22.  
  23.  
  24. # will match every resource ending in .pp (manifests files for instance)
  25. #
  26. # path ~ ^/path/to/resource
  27. # is essentially equivalent to path /path/to/resource
  28. #
  29. # environment:: restrict an ACL to a specific set of environments
  30. # method:: restrict an ACL to a specific set of methods
  31. # auth:: restrict an ACL to an authenticated or unauthenticated request
  32. # the default when unspecified is to restrict the ACL to authenticated requests
  33. # (ie exactly as if auth yes was present).
  34. #
  35.  
  36. ### Authenticated ACL - those applies only when the client
  37. ### has a valid certificate and is thus authenticated
  38.  
  39. # allow nodes to retrieve their own catalog (ie their configuration)
  40. path ~ ^/catalog/([^/]+)$
  41. method find
  42. allow *
  43.  
  44. # allow nodes to retrieve their own node definition
  45. path ~ ^/node/([^/]+)$
  46. method find
  47. allow $1
  48.  
  49. # allow all nodes to access the certificates services
  50. path /certificate_revocation_list/ca
  51. method find
  52. allow *
  53.  
  54. # allow all nodes to store their reports
  55. path /report
  56. method save
  57. allow *
  58.  
  59. # inconditionnally allow access to all files services
  60. # which means in practice that fileserver.conf will
  61. # still be used
  62. path /file
  63. allow *
  64.  
  65. ### Unauthenticated ACL, for clients for which the current master doesn't
  66. ### have a valid certificate; we allow authenticated users, too, because
  67. ### there isn't a great harm in letting that request through.
  68.  
  69. # allow access to the master CA
  70. path /certificate/ca
  71. auth any
  72. method find
  73. allow *
  74.  
  75. path /certificate/
  76. auth any
  77. method find
  78. allow *
  79.  
  80. path /certificate_request
  81. auth any
  82. method find, save
  83. allow *
  84.  
  85. # this one is not stricly necessary, but it has the merit
  86. # to show the default policy which is deny everything else
  87. path /
  88. auth any
  89.  
  90.  
  91. ------------
  92.  
  93. fileserver.conf
  94.  
  95. # This file consists of arbitrarily named sections/modules
  96. # defining where files are served from and to whom
  97.  
  98. # Define a section 'files'
  99. # Adapt the allow/deny settings to your needs. Order
  100. # for allow/deny does not matter, allow always takes precedence
  101. # over deny
  102. [files]
  103. path /etc/puppet/files
  104. allow *
  105. # deny *.evil.example.com
  106. # allow 192.168.0.0/24
  107.  
  108. [plugins]
  109. # allow *.example.com
  110. # deny *.evil.example.com
  111. # allow 192.168.0.0/24
Advertisement
Add Comment
Please, Sign In to add comment