Newbie questions

Jakub Wardyn <[email protected]> Sun, 3 Aug 2025 08:51:16 -0700 (PDT)
Newsgroups gmane.comp.sysutils.cfengine.general
Message-ID <[email protected]>
------=_Part_42728_1671617567.1754236276344
Content-Type: multipart/alternative; 
	boundary="----=_Part_42729_792518029.1754236276344"

------=_Part_42729_792518029.1754236276344
Content-Type: text/plain; charset="UTF-8"

Hello,
I'm a total newbie in CFEngine, I'm interested in learning but I have 
trouble understanding how to even start, and I'm beginning to think maybe 
CFEngine isn't what I need.

Right now I have a couple of servers, on which I want to deploy some 
services (some in Docker, some as regular processes), I want a solution 
where I can describe that declaratively, and have a e.g. git repository 
with "current state of everything that's running on my servers", I also 
want to automate stuff like setting up backups, updating the system, etc. 
It's all Linux for now, and I expect the number of servers to grow in the 
future.

I previously used Ansible and Salt but I found those to be very opaque, 
complex and fragile, I wanted a low-level solution and CFEngine really 
looks nice here. With ChatGPT's help I even got some code that I can run to 
deploy Docker service and it all makes sense to me.

What doesn't make sense though, is the massive number of stuff I get in my 
"masterfiles" directory (I think it's called MPF), and contradicting 
documentation.

I have Alpine Linux and Debian Linux, as hub and agent respectively. They 
both use different directories for CFEngine's files (/var/lib/cfengine vs 
/var/lib/cfengine3), and this causes errors during bootstrap, unless I 
symlink, which seems hacky. In addition documentation everywhere says that 
/var/cfengine should be used, which is not the case.

In addition - the number of stuff in MPF adds, what I think is, unnecessary 
complexity to my use case, ideally I'd probably copy some stuff like stdlib 
etc. but delete the rest. I tried to start with a small and simple 
promises.cf but I failed miserably due to some issues with relative paths 
access, the failsafe.cf requested relative paths, while the hub didn't 
allow me to define ACL for relative paths...

Anyway, I think what I really want to know is:
- Is there any "practical" guide for CFEngine which is reasonably recent, 
and can guide me through building small-scale stuff from the grounds up. 
I'd appreciate a link.
- Do I need MPF? If I have a git repo do I just copy MPF into it? What does 
MPF do for me? The very reason that I wanted to learn CFEngine is the 
simplicity and transparency of what it does, MPF seems to contradict that.
- How to deal with the differences between paths in different distros? 
Should I just roll out CFEngine manually? I thought I can just install 
CFEngine in anyway, and then bootstrap and it will figure everything out 
from there, seems like that's not the case. I hope the "hub" can tell the 
agents where to look for the policies? Or is the files structure just 
coupled together everywhere?
- And honestly, is CFEngine even the right tool for use cases like mine? I 
don't mind tinkering a bit and working in low-level stuff, but I hate 
fighting with the complexity of my tools. I want a simple low-level tool 
with which I build my own automation, not an "out-of-the-box" corporate 
solution for thousands of servers.

-- 
You received this message because you are subscribed to the Google Groups "help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com.

------=_Part_42729_792518029.1754236276344
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello,<br />I'm a total newbie in CFEngine, I'm interested in learning but =
I have trouble understanding how to even start, and I'm beginning to think =
maybe CFEngine isn't what I need.<br /><br />Right now I have a couple of s=
ervers, on which I want to deploy some services (some in Docker, some as re=
gular processes), I want a solution where I can describe that declaratively=
, and have a e.g. git repository with "current state of everything that's r=
unning on my servers", I also want to automate stuff like setting up backup=
s, updating the system, etc. It's all Linux for now, and I expect the numbe=
r of servers to grow in the future.<br /><br />I previously used Ansible an=
d Salt but I found those to be very opaque, complex and fragile, I wanted a=
 low-level solution and CFEngine really looks nice here. With ChatGPT's hel=
p I even got some code that I can run to deploy Docker service and it all m=
akes sense to me.<br /><br />What doesn't make sense though, is the massive=
 number of stuff I get in my "masterfiles" directory (I think it's called M=
PF), and contradicting documentation.<br /><br />I have Alpine Linux and De=
bian Linux, as hub and agent respectively. They both use different director=
ies for CFEngine's files (/var/lib/cfengine vs /var/lib/cfengine3), and thi=
s causes errors during bootstrap, unless I symlink, which seems hacky. In a=
ddition documentation everywhere says that /var/cfengine should be used, wh=
ich is not the case.<br /><br />In addition - the number of stuff in MPF ad=
ds, what I think is, unnecessary complexity to my use case, ideally I'd pro=
bably copy some stuff like stdlib etc. but delete the rest. I tried to star=
t with a small and simple promises.cf but I failed miserably due to some is=
sues with relative paths access, the failsafe.cf requested relative paths, =
while the hub didn't allow me to define ACL for relative paths...<br /><br =
/>Anyway, I think what I really want to know is:<br />- Is there any "pract=
ical" guide for CFEngine which is reasonably recent, and can guide me throu=
gh building small-scale stuff from the grounds up. I'd appreciate a link.<b=
r />- Do I need MPF? If I have a git repo do I just copy MPF into it? What =
does MPF do for me? The very reason that I wanted to learn CFEngine is the =
simplicity and transparency of what it does, MPF seems to contradict that.<=
br />- How to deal with the differences between paths in different distros?=
 Should I just roll out CFEngine manually? I thought I can just install CFE=
ngine in anyway, and then bootstrap and it will figure everything out from =
there, seems like that's not the case. I hope the "hub" can tell the agents=
 where to look for the policies? Or is the files structure just coupled tog=
ether everywhere?<br />- And honestly, is CFEngine even the right tool for =
use cases like mine? I don't mind tinkering a bit and working in low-level =
stuff, but I hate fighting with the complexity of my tools. I want a simple=
 low-level tool with which I build my own automation, not an "out-of-the-bo=
x" corporate solution for thousands of servers.<br />

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;help-cfengine&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">help-=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/=
help-cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com?utm_=
medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d/msgid/help-=
cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com</a>.<br /=
>

------=_Part_42729_792518029.1754236276344--

------=_Part_42728_1671617567.1754236276344--