Adoptable Cookbooks List

Looking for a cookbook to adopt? You can now see a list of cookbooks available for adoption!
List of Adoptable Cookbooks

Supermarket Belongs to the Community

Supermarket belongs to the community. While Chef has the responsibility to keep it running and be stewards of its functionality, what it does and how it works is driven by the community. The chef/supermarket repository will continue to be where development of the Supermarket application takes place. Come be part of shaping the direction of Supermarket by opening issues and pull requests or by joining us on the Chef Mailing List.

Select Badges

Select Supported Platforms

Select Status

RSS

tls (16) Versions 3.1.0

Deploy TLS certificates

Policyfile
Berkshelf
Knife
cookbook 'tls', '= 3.1.0', :supermarket
cookbook 'tls', '= 3.1.0'
knife supermarket install tls
knife supermarket download tls
README
Dependencies
Quality 33%

tls-cookbook

Chef cookbook
license

Chef cookbook to deploy SSL/TLS certificates (including root ones) on a system. Data is stored in the encrypted data bag which name is specified in the attribute node['tls']['data_bag_name'] (by default tls). Data bag item name matches node.chef_environment value.

Certificate files will be placed under the directory specified in attribute node['tls']['base_dir'] (by default /etc/chef-tls).

Root certificate files will be placed under system directories.

Encrypted data bag format

{
  "id": "development",
  "ca_certificates": {
    // Trusted Root CA
    // "name": "----- certificate data -----"
    "Custom_CA": "-----BEGIN CERTIFICATE-----\nMIIF0jCC........UwhJJgNX\n-----END CERTIFICATE-----",
    // other entries
  },
  "certificates": [
    {
      "name": "domain.tld-rsa", // Certificate name (optional)
      "domains": [ // Domain list
        "domain.tld",
        "www.domain.tld"
      ],
      "chain": [ // Certificate chain (from leaf to root, PEM encoded, new lines should be escaped)
        "-----BEGIN CERTIFICATE-----\nMIIFNjCC........4PcGNXXA\n-----END CERTIFICATE-----",
        "-----BEGIN CERTIFICATE-----\nMIIEkjCC........NFu0Qg==\n-----END CERTIFICATE-----"
      ],
      "private_key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIB........8tt8JA==\n-----END RSA PRIVATE KEY-----", // Certificate private key (PEM encoded, new lines should be escaped)
      "hpkp_pins": [ // HPKP pins (base64 encoded)
        "wZgbeR6b........",
        "bDSe0744........"
      ],
      "scts": { // SCTs (base64 encoded)
        "google_aviator": "AGj2mPgf........3nYNtNU=",
        "google_pilot": "AKS5CZC0........RnySxdE=",
        "google_rocketeer": "AO5Lvbd1........bdC+zlI="
      }
    },
    {
      // other entries
    }
  ]
}

Resources

tls_certificate

Certificate deployment is made by using tls_certificate resource. For example,

tls_certificate 'www.domain.tld' do
  action :deploy
end

Different software (e.g. Nginx, Postfix) will require paths to deployed certificates, private keys and SCTs. To obtain these paths, ::ChefCookbook::TLS helper should be used. Below is the example:

tls_item = ::ChefCookbook::TLS.new(node).certificate_entry('www.domain.tld')

tls_item.certificate_path  # Get path to the certificate
tls_item.certificate_private_key_path  # Get path to the certificate's private key
tls_item.scts_dir  # Get path to the folder with deployed SCTs
tls_item.hpkp_pins  # Get array of HPKP pins

If there are several certificates for the same set of domains (e.g. RSA and ECDSA ones), both tls_certificate resource and certificate_entry helper method will operate with the first item found in the data bag. To pick out the exact certificate, you should use either tls_rsa_certificate resource / rsa_certificate_entry helper method or tls_ec_certificate resource / ec_certificate_entry helper method.

tls_rsa_certificate

tls_rsa_certificate 'www.domain.tld' do
  action :deploy
end
tls_item = ::ChefCookbook::TLS.new(node).rsa_certificate_entry('www.domain.tld')

tls_ec_certificate

tls_ec_certificate 'www.domain.tld' do
  action :deploy
end
tls_item = ::ChefCookbook::TLS.new(node).ec_certificate_entry('www.domain.tld')

tls_ca_certificate

Installing/uninstalling CA certificates only works on Ubuntu systems.
To obtain path to CA certificate bundle, ::ChefCookbook::TLS helper should be used. Below is the example:

tls_helper = ::ChefCookbook::TLS.new(node)

tls_helper.ca_bundle_path  # Get CA certificate bundle path

Installing

tls_ca_certificate 'Custom_CA' do
  action :install
end

Uninstalling

tls_ca_certificate 'Custom_CA' do
  action :uninstall
end

License

MIT @ Alexander Pyatkin

Collaborator Number Metric
            

3.1.0 failed this metric

Failure: Cookbook has 0 collaborators. A cookbook must have at least 2 collaborators to pass this metric.

Contributing File Metric
            

3.1.0 failed this metric

Failure: To pass this metric, your cookbook metadata must include a source url, the source url must be in the form of https://github.com/user/repo, and your repo must contain a CONTRIBUTING.md file

Foodcritic Metric
            

3.1.0 failed this metric

FC108: Resource should not define a property named 'name': tls/resources/ca_certificate.rb:3
Run with Foodcritic Version 14.3.0 with tags metadata,correctness ~FC031 ~FC045 and failure tags any

No Binaries Metric
            

3.1.0 passed this metric

Testing File Metric
            

3.1.0 failed this metric

Failure: To pass this metric, your cookbook metadata must include a source url, the source url must be in the form of https://github.com/user/repo, and your repo must contain a TESTING.md file

Version Tag Metric
            

3.1.0 passed this metric