summaryrefslogtreecommitdiffstats
path: root/man/bcfg2.conf.5
blob: 33c5d83f8da79ce51ad313415bc887ca99b027f6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
.
.TH "BCFG2\.CONF" "5" "October 2012" "" ""
.
.SH "NAME"
\fBbcfg2\.conf\fR \- configuration parameters for Bcfg2
.
.SH "DESCRIPTION"
\fBbcfg2\.conf\fR includes configuration parameters for the Bcfg2 server and client\.
.
.SH "FILE FORMAT"
The file is INI\-style and consists of sections and options\. A section begins with the name of the sections in square brackets and continues until the next section begins\.
.
.P
Options are specified in the form "name=value"\.
.
.P
The file is line\-based each newline\-terminated line represents either a comment, a section name or an option\.
.
.P
Any line beginning with a hash (#) is ignored, as are lines containing only whitespace\.
.
.SH "SERVER OPTIONS"
These options are only necessary on the Bcfg2 server\. They are specified in the \fB[server]\fR section of the configuration file\.
.
.TP
\fBrepository\fR
Specifies the path to the Bcfg2 repository containing all of the configuration specifications\. The repository should be created using the \fBbcfg2\-admin init\fR command\.
.
.TP
\fBfilemonitor\fR
The file monitor used to watch for changes in the repository\. The default is the best available monitor\. The following values are valid:
.
.IP
\fBinotify\fR, \fBgamin\fR, \fBfam\fR, \fBpseudo\fR
.
.TP
\fBignore_files\fR
A comma\-separated list of globs that should be ignored by the file monitor\. Default values are:
.
.IP
\fB*~\fR, \fB*#\fR, \fB\.#*\fR, \fB*\.swp\fR, \fB\.*\.swx\fR, \fBSCCS\fR, \fB\.svn\fR, \fB4913\fR, \fB\.gitignore\fR
.
.TP
\fBlisten_all\fR
This setting tells the server to listen on all available interfaces\. The default is to only listen on those interfaces specified by the bcfg2 setting in the components section of \fBbcfg2\.conf\fR\.
.
.TP
\fBplugins\fR
A comma\-delimited list of enabled server plugins\. Currently available plugins are:
.
.IP
\fBAccount\fR, \fBActions\fR, \fBBase\fR, \fBBundler\fR, \fBBzr\fR, \fBCfg\fR, \fBCvs\fR, \fBDarcs\fR, \fBDBStats\fR, \fBDecisions\fR, \fBDeps\fR, \fBEditor\fR, \fBFossil\fR, \fBGit\fR, \fBGroupPatterns\fR, \fBHg\fR, \fBHostbase\fR, \fBMetadata\fR, \fBNagiosGen\fR, \fBOhai\fR, \fBPackages\fR, \fBPkgmgr\fR, \fBProbes\fR, \fBProperties\fR, \fBRules\fR, \fBSnapshots\fR, \fBSSHbase\fR, \fBSvn\fR, \fBSvn2\fR, \fBTCheetah\fR, \fBTGenshi\fR, \fBTrigger\fR
.
.IP
Descriptions of each plugin can be found in their respective sections below\.
.
.TP
\fBprefix\fR
Specifies a prefix if the Bcfg2 installation isn’t placed in the default location (e\.g\. /usr/local)\.
.
.TP
\fBbackend\fR
Specifies which server core backend to use\. Current available options are:
.
.IP
\fBcherrypy\fR, \fBbuiltin\fR, \fBbest\fR
.
.IP
The default is \fBbest\fR, which is currently an alias for \fBbuiltin\fR\. More details on the backends can be found in the official documentation\.
.
.TP
\fBuser\fR
The username or UID to run the daemon as\. Default is \fB0\fR
.
.TP
\fBgroup\fR
The group name or GID to run the daemon as\. Default is \fB0\fR
.
.SS "Account Plugin"
The account plugin manages authentication data, including the following\.
.
.IP "\(bu" 4
\fB/etc/passwd\fR
.
.IP "\(bu" 4
\fB/etc/group\fR
.
.IP "\(bu" 4
\fB/etc/security/limits\.conf\fR
.
.IP "\(bu" 4
\fB/etc/sudoers\fR
.
.IP "\(bu" 4
\fB/root/\.ssh/authorized_keys\fR
.
.IP "" 0
.
.SS "Base Plugin"
A structure plugin that provides the ability to add lists of unrelated entries into client configuration entry inventories\. Base works much like Bundler in its file format\. This structure plugin is good for the pile of independent configs needed for most actual systems\.
.
.SS "Bundler Plugin"
Bundler is used to describe groups of inter\-dependent configuration entries, such as the combination of packages, configuration files, and service activations that comprise typical Unix daemons\. Bundles are used to add groups of configuration entries to the inventory of client configurations, as opposed to describing particular versions of those entries\.
.
.SS "Bzr Plugin"
The Bzr plugin allows you to track changes to your Bcfg2 repository using a GNU Bazaar version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "Cfg Plugin"
The Cfg plugin provides a repository to describe configuration file contents for clients\. In its simplest form, the Cfg repository is just a directory tree modeled off of the directory tree on your client machines\.
.
.SS "Cvs Plugin (experimental)"
The Cvs plugin allows you to track changes to your Bcfg2 repository using a Concurrent version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "Darcs Plugin (experimental)"
The Darcs plugin allows you to track changes to your Bcfg2 repository using a Darcs version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "DBStats Plugin"
Direct to database statistics plugin\.
.
.SS "Decisions Plugin"
The Decisions plugin has support for a centralized set of per\-entry installation decisions\. This approach is needed when particular changes are deemed "\fIhigh risk\fR"; this gives the ability to centrally specify these changes, but only install them on clients when administrator supervision is available\.
.
.SS "Deps Plugin"
The Deps plugin allows you to make a series of assertions like "Package X requires Package Y (and optionally also Package Z etc\.)"
.
.SS "Editor Plugin"
The Editor plugin attempts to allow you to partially manage configuration for a file\. Its use is not recommended and not well documented\.
.
.SS "Fossil Plugin"
The Fossil plugin allows you to track changes to your Bcfg2 repository using a Fossil SCM version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "Git Plugin"
The Git plugin allows you to track changes to your Bcfg2 repository using a Git version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "GroupPatterns Plugin"
The GroupPatterns plugin is a connector that can assign clients group membership based on patterns in client hostnames\.
.
.SS "Hg Plugin (experimental)"
The Hg plugin allows you to track changes to your Bcfg2 repository using a Mercurial version control backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "Hostbase Plugin"
The Hostbase plugin is an IP management system built on top of Bcfg2\.
.
.SS "Metadata Plugin"
The Metadata plugin is the primary method of specifying Bcfg2 server metadata\.
.
.SS "NagiosGen Plugin"
NagiosGen is a Bcfg2 plugin that dynamically generates Nagios configuration files based on Bcfg2 data\.
.
.SS "Ohai Plugin (experimental)"
The Ohai plugin is used to detect information about the client operating system\. The data is reported back to the server using JSON\.
.
.SS "Packages Plugin"
The Packages plugin is an alternative to Pkgmgr for specifying package entries for clients\. Where Pkgmgr explicitly specifies package entry information, Packages delegates control of package version information to the underlying package manager, installing the latest version available from through those channels\.
.
.SS "Pkgmgr Plugin"
The Pkgmgr plugin resolves the Abstract Configuration Entity "Package" to a package specification that the client can use to detect, verify and install the specified package\.
.
.SS "Probes Plugin"
The Probes plugin gives you the ability to gather information from a client machine before you generate its configuration\. This information can be used with the various templating systems to generate configuration based on the results\.
.
.SS "Properties Plugin"
The Properties plugin is a connector plugin that adds information from properties files into client metadata instances\.
.
.SS "Rules Plugin"
The Rules plugin provides literal configuration entries that resolve the abstract configuration entries normally found in the Bundler and Base plugins\. The literal entries in Rules are suitable for consumption by the appropriate client drivers\.
.
.SS "Snapshots Plugin"
The Snapshots plugin stores various aspects of a client’s state when the client checks in to the server\.
.
.SS "SSHbase Plugin"
The SSHbase generator plugin manages ssh host keys (both v1 and v2) for hosts\. It also manages the ssh_known_hosts file\. It can integrate host keys from other management domains and similarly export its keys\.
.
.SS "Svn Plugin"
The Svn plugin allows you to track changes to your Bcfg2 repository using a Subversion backend\. Currently, it enables you to get revision information out of your repository for reporting purposes\.
.
.SS "Svn2 Plugin"
The Svn2 plugin extends on the capabilities in the Svn plugin\. It provides Update and Commit methods which provide hooks for modifying subversion\-backed Bcfg2 repositories\.
.
.SS "TCheetah Plugin"
The TCheetah plugin allows you to use the cheetah templating system to create files\. It also allows you to include the results of probes executed on the client in the created files\.
.
.SS "TGenshi Plugin"
The TGenshi plugin allows you to use the Genshi templating system to create files\. It also allows you to include the results of probes executed on the client in the created files\.
.
.SS "Trigger Plugin"
The Trigger plugin provides a method for calling external scripts when clients are configured\.
.
.SH "CLIENT OPTIONS"
These options only affect client functionality, specified in the \fB[client]\fR section\.
.
.TP
\fBdecision\fR
Specify the server decision list mode (whitelist or blacklist)\. (This settiing will be ignored if the client is called with the \-f option\.)
.
.TP
\fBdrivers\fR
Specify tool driver set to use\. This option can be used to explicitly specify the client tool drivers you want to use when the client is run\.
.
.TP
\fBparanoid\fR
Run the client in paranoid mode\.
.
.TP
\fBprofile\fR
Assert the given profile for the host\.
.
.SH "COMMUNICATION OPTIONS"
Specified in the \fB[communication]\fR section\. These options define settings used for client\-server communication\.
.
.TP
\fBca\fR
The path to a file containing the CA certificate\. This file is required on the server, and optional on clients\. However, if the cacert is not present on clients, the server cannot be verified\.
.
.TP
\fBcertificate\fR
The path to a file containing a PEM formatted certificate which signs the key with the ca certificate\. This setting is required on the server in all cases, and required on clients if using client certificates\.
.
.TP
\fBkey\fR
Specifies the path to a file containing the SSL Key\. This is required on the server in all cases, and required on clients if using client certificates\.
.
.TP
\fBpassword\fR
Required on both the server and clients\. On the server, sets the password clients need to use to communicate\. On a client, sets the password to use to connect to the server\.
.
.TP
\fBprotocol\fR
Communication protocol to use\. Defaults to xmlrpc/ssl\.
.
.TP
\fBretries\fR
A client\-only option\. Number of times to retry network communication\. Default is 3 retries\.
.
.TP
\fBretry_delay\fR
A client\-only option\. Number of seconds to wait in between retrying network communication\. Default is 1 second\.
.
.TP
\fBserverCommonNames\fR
A client\-only option\. A colon\-separated list of Common Names the client will accept in the SSL certificate presented by the server\.
.
.TP
\fBtimeout\fR
A client\-only option\. The network communication timeout\.
.
.TP
\fBuser\fR
A client\-only option\. The UUID of the client\.
.
.SH "COMPONENT OPTIONS"
Specified in the \fB[components]\fR section\.
.
.TP
\fBbcfg2\fR
URL of the server\. On the server this specifies which interface and port the server listens on\. On the client, this specifies where the client will attempt to contact the server\.
.
.IP
e\.g\. \fBbcfg2 = https://10\.3\.1\.6:6789\fR
.
.TP
\fBencoding\fR
Text encoding of configuration files\. Defaults to UTF\-8\.
.
.TP
\fBlockfile\fR
The path to the client lock file, which is used to ensure that only one Bcfg2 client runs at a time on a single client\.
.
.SH "LOGGING OPTIONS"
Specified in the \fB[logging]\fR section\. These options control the server logging functionality\.
.
.TP
\fBdebug\fR
Whether or not to enable debug\-level log output\. Default is false\.
.
.TP
\fBpath\fR
Server log file path\.
.
.TP
\fBsyslog\fR
Whether or not to send logging data to syslog\. Default is true\.
.
.TP
\fBverbose\fR
Whether or not to enable verbose log output\. Default is false\.
.
.SH "MDATA OPTIONS"
Specified in the \fB[mdata]\fR section\. These options affect the default metadata settings for Paths with type=’file’\.
.
.TP
\fBowner\fR
Global owner for Paths (defaults to root)
.
.TP
\fBgroup\fR
Global group for Paths (defaults to root)
.
.TP
\fBperms\fR
Global permissions for Paths (defaults to 644)
.
.TP
\fBsecontext\fR
Global SELinux context for Path entries (defaults to \fB__default__\fR, which restores the expected context)
.
.TP
\fBparanoid\fR
Global paranoid settings for Paths (defaults to false)
.
.TP
\fBsensitive\fR
Global sensitive settings for Paths (defaults to false)
.
.TP
\fBimportant\fR
Global important settings for Paths\. Defaults to false, and anything else is probably not a good idea\.
.
.SH "PACKAGES OPTIONS"
The following options are specified in the \fB[packages]\fR section of the configuration file\.
.
.TP
\fBresolver\fR
Enable dependency resolution\. Default is 1 (true)\.
.
.TP
\fBmetadata\fR
Enable metadata processing\. Default is 1 (true)\. If metadata is disabled, it’s implied that resolver is also disabled\.
.
.TP
\fByum_config\fR
The path at which to generate Yum configs\. No default\.
.
.TP
\fBapt_config\fR
The path at which to generate APT configs\. No default\.
.
.TP
\fBgpg_keypath\fR
The path on the client where RPM GPG keys will be copied before they are imported on the client\. Default is \fB/etc/pki/rpm\-gpg\fR\.
.
.TP
\fBversion\fR
Set the version attribute used when binding Packages\. Default is auto\.
.
.P
The following options are specified in the \fB[packages:yum]\fR section of the configuration file\.
.
.TP
\fBuse_yum_libraries\fR
By default, Bcfg2 uses an internal implementation of Yum’s dependency resolution and other routines so that the Bcfg2 server can be run on a host that does not support Yum itself\. If you run the Bcfg2 server on a machine that does have Yum libraries, however, you can enable use of those native libraries in Bcfg2 by setting this to 1\.
.
.TP
\fBhelper\fR
Path to bcfg2\-yum\-helper\. By default, Bcfg2 looks first in $PATH and then in \fB/usr/sbin/bcfg2\-yum\-helper\fR for the helper\.
.
.P
All other options in the \fB[packages:yum]\fR section will be passed along verbatim to the Yum configuration if you are using the native Yum library support\.
.
.P
The following options are specified in the \fB[packages:pulp]\fR section of the configuration file\.
.
.TP
\fBusername\fR
The username of a Pulp user that will be used to register new clients and bind them to repositories\.
.
.TP
\fBpassword\fR
The password of a Pulp user that will be used to register new clients and bind them to repositories\.
.
.SH "PARANOID OPTIONS"
These options allow for finer\-grained control of the paranoid mode on the Bcfg2 client\. They are specified in the \fB[paranoid]\fR section of the configuration file\.
.
.TP
\fBpath\fR
Custom path for backups created in paranoid mode\. The default is in \fB/var/cache/bcfg2\fR\.
.
.TP
\fBmax_copies\fR
Specify a maximum number of copies for the server to keep when running in paranoid mode\. Only the most recent versions of these copies will be kept\.
.
.SH "SNAPSHOTS OPTIONS"
Specified in the \fB[snapshots]\fR section\. These options control the server snapshots functionality\.
.
.TP
\fBdriver\fR
sqlite
.
.TP
\fBdatabase\fR
The name of the database to use for statistics data\.
.
.IP
eg: \fB$REPOSITORY_DIR/etc/bcfg2\.sqlite\fR
.
.SH "SSLCA OPTIONS"
These options are necessary to configure the SSLCA plugin and can be found in the \fB[sslca_default]\fR section of the configuration file\.
.
.TP
\fBconfig\fR
Specifies the location of the openssl configuration file for your CA\.
.
.TP
\fBpassphrase\fR
Specifies the passphrase for the CA’s private key (if necessary)\. If no passphrase exists, it is assumed that the private key is stored unencrypted\.
.
.TP
\fBchaincert\fR
Specifies the location of your ssl chaining certificate\. This is used when pre\-existing certifcate hostfiles are found, so that they can be validated and only regenerated if they no longer meet the specification\. If you’re using a self signing CA this would be the CA cert that you generated\.
.
.SH "DATABASE OPTIONS"
Server\-only, specified in the \fB[database]\fR section\. These options control the database connection of the server\.
.
.TP
\fBengine\fR
The database engine used by the statistics module\. One of the following:
.
.IP
\fBpostgresql\fR, \fBmysql\fR, \fBsqlite3\fR, \fBado_mssql\fR
.
.TP
\fBname\fR
The name of the database to use for statistics data\. If ‘database_engine’ is set to ‘sqlite3’ this is a file path to sqlite file and defaults to \fB$REPOSITORY_DIR/etc/brpt\.sqlite\fR\.
.
.TP
\fBuser\fR
User for database connections\. Not used for sqlite3\.
.
.TP
\fBpassword\fR
Password for database connections\. Not used for sqlite3\.
.
.TP
\fBhost\fR
Host for database connections\. Not used for sqlite3\.
.
.TP
\fBport\fR
Port for database connections\. Not used for sqlite3\.
.
.TP
\fBtime_zone\fR
Specify a time zone other than that used on the system\. (Note that this will cause the Bcfg2 server to log messages in this time zone as well)\.
.
.SH "SEE ALSO"
bcfg2(1), bcfg2\-server(8)