Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Error message:
- info: Caching catalog for 10.0.0.205
- info: Applying configuration version '1327058802'
- err: /Stage[main]//Node[10.0.0.205]/File[/home/ubuntu/teste]: Could not evaluate: Error 400 on SERVER: Not authorized to call find on /file_metadata/files/teste Could not retrieve file metadata for puppet:///files/teste: Error 400 on SERVER: Not authorized to call find on /file_metadata/files/teste at /etc/puppet/manifests/site.pp:24
- notice: Finished catalog run in 0.08 seconds
- -----
- site.pp
- node '10.0.0.205'{
- file {"/home/ubuntu/teste":
- source => 'puppet:///files/teste'
- }
- }
- ---------
- auth.conf
- # will match every resource ending in .pp (manifests files for instance)
- #
- # path ~ ^/path/to/resource
- # is essentially equivalent to path /path/to/resource
- #
- # environment:: restrict an ACL to a specific set of environments
- # method:: restrict an ACL to a specific set of methods
- # auth:: restrict an ACL to an authenticated or unauthenticated request
- # the default when unspecified is to restrict the ACL to authenticated requests
- # (ie exactly as if auth yes was present).
- #
- ### Authenticated ACL - those applies only when the client
- ### has a valid certificate and is thus authenticated
- # allow nodes to retrieve their own catalog (ie their configuration)
- path ~ ^/catalog/([^/]+)$
- method find
- allow *
- # allow nodes to retrieve their own node definition
- path ~ ^/node/([^/]+)$
- method find
- allow $1
- # allow all nodes to access the certificates services
- path /certificate_revocation_list/ca
- method find
- allow *
- # allow all nodes to store their reports
- path /report
- method save
- allow *
- # inconditionnally allow access to all files services
- # which means in practice that fileserver.conf will
- # still be used
- path /file
- allow *
- ### Unauthenticated ACL, for clients for which the current master doesn't
- ### have a valid certificate; we allow authenticated users, too, because
- ### there isn't a great harm in letting that request through.
- # allow access to the master CA
- path /certificate/ca
- auth any
- method find
- allow *
- path /certificate/
- auth any
- method find
- allow *
- path /certificate_request
- auth any
- method find, save
- allow *
- # this one is not stricly necessary, but it has the merit
- # to show the default policy which is deny everything else
- path /
- auth any
- ------------
- fileserver.conf
- # This file consists of arbitrarily named sections/modules
- # defining where files are served from and to whom
- # Define a section 'files'
- # Adapt the allow/deny settings to your needs. Order
- # for allow/deny does not matter, allow always takes precedence
- # over deny
- [files]
- path /etc/puppet/files
- allow *
- # deny *.evil.example.com
- # allow 192.168.0.0/24
- [plugins]
- # allow *.example.com
- # deny *.evil.example.com
- # allow 192.168.0.0/24
Advertisement
Add Comment
Please, Sign In to add comment