Sometimes, we disable the puppet agent with puppet agent --disable; we should have an icinga check for this, to avoid forgetting to enable it again.
I suggest warning after 4 hours, and erroring after 24 hours.
Sometimes, we disable the puppet agent with puppet agent --disable; we should have an icinga check for this, to avoid forgetting to enable it again.
I suggest warning after 4 hours, and erroring after 24 hours.
rSPSITE puppet-swh-site | |||
D5065 | rSPSITE8bc7ef05cca4 icinga: grant access to private puppet directories | ||
D5043 | rSPSITEe3c3a3dc844a icinga: monitor puppet agent activation |
The file /var/lib/puppet/state/agent_disabled.lock can be checked to detect if puppet is disable or not.
After puppet has added the group to the user nagios[1], the icinga services needed to be restarted.
# clush -b -w @staging 'systemctl restart icinga2' # clush -b -w @all 'systemctl restart icinga2'
[1] The group was manually added on the hosts where puppet was disable (worker01 and saatchi). There is still giverny, but I kept it untouched