Online course for setting up your Manageable Puppet Infrastructure

Written by Ger Apeldoorn. Posted in Geen categorie

I see people struggle with their Puppet setups over and over again. It doesn’t fit right, makes it hard for people to work together and changes are risky and complicated. The smallest change might be the one that makes your servers keel over.

I have found that there is a sound infrastructure that has proven its robustness and flexibility in many companies.

Unfortunately, there are a lot of people that are still struggling. I have done talks about the Manageable Puppet Infrastructure at conferences and have had setup instructions on my site for years, but although some people could get by with this, it was still lacking a bit.

In the last few weeks, I have been working on an online course at This course (Build your own Manageable Puppet Infrastructure) consists of hours of practical video lectures and you can follow me step-by-step to setup your own MPI.

The end-result of taking this course is a production-ready Manageable Puppet Infrastructure.

I’ll even give you a 20% discount when you use this link to sign up, so it will only cost you €60. How about that!



Written by Ger Apeldoorn. Posted in Sysadmin

When upgrading the Puppet master (or messing things up) it can be useful to have a quick script that enables the firewall and stops incoming connections.

This is a simple script that enables that. Note that it assumes that the normal situation does not have any firewall-rules running.





New developer environment (script)

Written by Ger Apeldoorn. Posted in Geen categorie

If you want to add a new developer-environment, it can be quite a hassle.

Here is a script to help you set it up, make sure that the user is known in Gerrit and that the SSH key is set up. Also, the repos must be present of course!

Make sure you understand what this script does BEFORE you run it!

MPI – Managing multiple customers within a single environment

Written by Ger Apeldoorn. Posted in Manageable Puppet Infrastructure


This is set in the Manageable Puppet Infrastructure, but should be quite useable if you’re not using it.

You want to manage multiple clients within a single environment. (You probably don’t want to create seperate environments or puppetmasters, because that creates quite a bit of overhead in the long run).

But how do we keep things flexible? It’s quite simple, use Hiera and classes in a smart way and you’re there!

One note; this simple setup only works if you do not have any naming conflicts in the modules. e.g. customer1 needs puppetlabs/apache and another needs another module named apache. In that case, you do need seperate environments.

Get that $customer variable filled

You’ll need a way to let Puppet know what customer a node belongs to. There are several ways:

Facter variables can be overridden quite easily. Use the ENC or Hiera!

  • Getting the info from Hiera, see below.
  • Set it from the ENC.

Adding a global $customer variable

In my site.pp:

Example: hieradata/hosts/

That’s an easy way to get the $customer (global) variable filled!

Putting it to use!


With the MPI, you’ve created a baserole that applies to all hosts.

We can still use that, just be aware that those resources/includes apply to ALL customers.

Also, we’d like a baseclass for each customer. Within the roles-module, that’s a piece of cake.


You can add a level for customer-specific settings.

Now, we can add a yaml file for each customer and assign the role::customer::base there.

Example: hieradata/customer/mycustomer1.yaml

Of course, you can add other customer-specific settings as well here!

Feedback is welcome, leave a message!

Upcoming: talk at PuppetCamp and FOSDEM

Written by Ger Apeldoorn. Posted in Nieuws

PuppetCamp last year

My talk @PuppetCamp last year

At January 28th, there will be a PuppetCamp in Amsterdam. Last year was a huge success with a lot of interesting talks and like-minded people.

I will be doing a talk about the Manageable Puppet Infrastructure setup that has evolved during my consultancy jobs. A technical breakout of this setup I can be found on this website.

A few days later, I will be doing a shortened version of this talk in the configuration management room at FOSDEM.

I am looking forward to these events and am very happy to participate!

Praatje op de Puppet User Group en FOSDEM

Written by Ger Apeldoorn. Posted in Nieuws

Vorige week ben ik bij een bijeenkomst geweest van de Puppet User Group. Deze werd gehouden bij de provider/hoster

Ik mocht er iets over Puppet vertellen, voor meer informatie zie het artikel op het blog van Byte.

Overigens mag ik deze presentatie ook houden op de Europese open source conferentie FOSDEM.