Skip to content
This repository has been archived by the owner on Sep 19, 2022. It is now read-only.

Commit

Permalink
Fix #4; enable Nexus to use reserved ports
Browse files Browse the repository at this point in the history
This change allows the Nexus service to bind reserved ports (< 1024)
and answer requests on default HTTP (80) and HTTPS (443) ports.
  • Loading branch information
Taciano Tres committed Mar 30, 2018
1 parent 5365661 commit 07a73d5
Show file tree
Hide file tree
Showing 5 changed files with 51 additions and 2 deletions.
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -232,6 +232,12 @@ Type: String

Java's desired distribution

#### `use_reserved_ports`

Type: Boolean

Whether reserved ports (80 and 443) should be used. Default to false

### Hiera Keys

#### Common
Expand Down
12 changes: 10 additions & 2 deletions manifests/config.pp
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,14 @@
$nexus_config_dir = "${nexus::nexus_data_path}/nexus3/etc"
$nexus_config_file = "${nexus::nexus_data_path}/nexus3/etc/nexus.properties"

if $nexus::use_reserved_ports {
$real_http_port = 80
$real_https_port = 443
} else {
$real_http_port = $nexus::http_port
$real_https_port = $nexus::https_port
}

file { $nexus_config_dir:
ensure => directory,
owner => $nexus::nexus_user,
Expand All @@ -28,8 +36,8 @@
owner => $nexus::nexus_user,
group => $nexus::nexus_group,
content => epp('nexus/nexus.properties.epp', {
http_port => $nexus::http_port,
https_port => $nexus::https_port,
http_port => $real_http_port,
https_port => $real_https_port,
enable_https => $nexus::enable_https,
listen_address => $nexus::listen_address,
}),
Expand Down
2 changes: 2 additions & 0 deletions manifests/init.pp
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
# @param [String] https_keystore_password Password to access the keystore
# @param [Boolean] manage_java Whether this module will manage Java or not
# @param [String] java_distribution Java's desired distribution
# @param [Boolean] use_reserved_ports Whether reserved ports (80 and 443) should be used. Default to false
#
class nexus (
String $nexus_user,
Expand All @@ -47,6 +48,7 @@
Boolean $enable_https = false,
String $https_keystore = '',
String $https_keystore_password = '',
Boolean $use_reserved_ports = false,
Boolean $manage_java = true,
String $java_distribution = 'jre'
) {
Expand Down
25 changes: 25 additions & 0 deletions manifests/java.pp
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,29 @@
distribution => $nexus::java_distribution,
}

$java_path = "/etc/alternatives/${nexus::java_distribution}"

if $nexus::use_reserved_ports {
ldconfig::entry { 'java':
paths => [
"${java_path}/lib/amd64/jli",
"${java_path}/lib/i386/jli",
],
require => [
Class['java'],
],
}

# http://man7.org/linux/man-pages/man7/capabilities.7.html
file_capability { "${java_path}/bin/java":
ensure => present,
capability => [
'cap_net_bind_service=epi',
],
require => [
Ldconfig::Entry['java'],
],
}
}

}
8 changes: 8 additions & 0 deletions metadata.json
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,14 @@
},
{
"name":"puppet/archive"
},
{
"name":"crayfishx/ldconfig",
"version_requirement": ">= 0.1.0 < 2.0.0"
},
{
"name":"stm/file_capability",
"version_requirement": ">= 1.0.1 < 2.0.0"
}
],
"pdk-version": "1.2.1",
Expand Down

0 comments on commit 07a73d5

Please sign in to comment.