0
votes

I have an application which requires a local account to be required for the configuration. I have created a module inside that I have 2 folders:

  1. files
  2. manifests

Under manifests init file I have the below code:

class xyz {
  exec { ' app_config':
    command => ' C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe -file c:\provisioning\modules\xyz\files\config1.ps1 '
  }
}

Under files folder there are 2 files:

  1. config1.ps1
  2. app_execute.bat

In config1.ps1 I am creating a local user:

$user = $env:COMPUTERNAME/Testing

$Credentials = New-Object -TypeName System.Management.Automation.PScredential -ArgumentList $user, ("test@3456", | ConvertTo-SecureString -AsPlainText -Force)

Start-Process C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe -Credential $Credentials -ArgumentList " Start-Process C:\Windows\System32\cmd.exe -File c:\provisioning\c:\provisioning\modules\xyz\files\app_execute.bat "

In app_execute.bat

c:\puppet\app.bat -f c:\puppet\responsefile.rsp

The log file shows that the PowerShell file config1.ps1 got executed successfully, but the application log file is not getting generated, but when executed manually the config1.ps1 the app will get configured.

Not sure, in config1.ps1, I am using a Start-Process which will create a separate process using the local account.

I think Puppet is not waiting for the above config1.ps1 to be completed succesfully.

Not sure why it is coming out without executing fully, Is there any condition, as we need to execute only one file inside init, as I am initiating 2 processes.

1
An exec resource, which starts a powershell script, which starts a PowerShell process, which starts a CMD process, which runs a batch file (with an invalid path), which runs another batch file, which processes some kind of response file. Wow. Just ... wow! My recommendation is: throw it away and start over. Like, from scratch. Consider using user resources for creating local users this time. - Ansgar Wiechers
@AnsgarWiechers, Thanks a lot with the input, I will try out the user resources and will check. - Shivayogi
@AnsgarWiechers, I used the user resource option, but it is throwing error, I have raised a ticket stackoverflow.com/questions/39653659/… for the same - Shivayogi

1 Answers

1
votes

For your command, this is what worked for me and I copy it throughout my work with Puppet:

command  => 'powershell -ExecutionPolicy RemoteSigned -file C:\<path to .ps1>'

What's key to remember:

  1. You can only use .ps1 files with the -File option here
  2. You can add anything Powershell within this .ps1 so utilize the PowerShell ISE to the best of your ability. A great resource to build your powershell scripts.
  3. Create a facts.d within the like directory that contains your manifests directory. Then create a batch file that checks if a file or directory exists, which is a simple way of accomplishing the generation of a fact. This might be hard in your case when checking for a user creation, but remember to ECHO user_creation_need=true or =false
  4. Test in a VM. This step is really crucial and I won't go into details, but as long as you can quickly switch back to a known good test state, the successful implementation of your Puppet work will be more certain. Look into Disk2Vhd and VirtualBox.

https://docs.puppet.com/puppet/4.3/reference/quick_start_user_group.html

Now, creating users is very awesome in Puppet because you don't need any of the directions above. Instead:

class user_group_creator {
  group {'Cool People':
    name       => 'Cool People',
    members    => ['User1','User3'],
    ensure     => present,
  }
  user {'User2':
    ensure           => present,
    name             => 'User2',
    password         => 'Password',
    password_max_age => '99999',
    before           => Group['Cool People'],
    groups           => 'Cool People',
 } 
}

Let me know how this helps or what you don't understand! Puppet can be a beast at times!