Newbie questions
Jakub Wardyn <[email protected]> Sun, 3 Aug 2025 08:51:16 -0700 (PDT)
| Newsgroups | gmane.comp.sysutils.cfengine.general |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_42728_1671617567.1754236276344 Content-Type: multipart/alternative; boundary="----=_Part_42729_792518029.1754236276344" ------=_Part_42729_792518029.1754236276344 Content-Type: text/plain; charset="UTF-8" Hello, I'm a total newbie in CFEngine, I'm interested in learning but I have trouble understanding how to even start, and I'm beginning to think maybe CFEngine isn't what I need. Right now I have a couple of servers, on which I want to deploy some services (some in Docker, some as regular processes), I want a solution where I can describe that declaratively, and have a e.g. git repository with "current state of everything that's running on my servers", I also want to automate stuff like setting up backups, updating the system, etc. It's all Linux for now, and I expect the number of servers to grow in the future. I previously used Ansible and Salt but I found those to be very opaque, complex and fragile, I wanted a low-level solution and CFEngine really looks nice here. With ChatGPT's help I even got some code that I can run to deploy Docker service and it all makes sense to me. What doesn't make sense though, is the massive number of stuff I get in my "masterfiles" directory (I think it's called MPF), and contradicting documentation. I have Alpine Linux and Debian Linux, as hub and agent respectively. They both use different directories for CFEngine's files (/var/lib/cfengine vs /var/lib/cfengine3), and this causes errors during bootstrap, unless I symlink, which seems hacky. In addition documentation everywhere says that /var/cfengine should be used, which is not the case. In addition - the number of stuff in MPF adds, what I think is, unnecessary complexity to my use case, ideally I'd probably copy some stuff like stdlib etc. but delete the rest. I tried to start with a small and simple promises.cf but I failed miserably due to some issues with relative paths access, the failsafe.cf requested relative paths, while the hub didn't allow me to define ACL for relative paths... Anyway, I think what I really want to know is: - Is there any "practical" guide for CFEngine which is reasonably recent, and can guide me through building small-scale stuff from the grounds up. I'd appreciate a link. - Do I need MPF? If I have a git repo do I just copy MPF into it? What does MPF do for me? The very reason that I wanted to learn CFEngine is the simplicity and transparency of what it does, MPF seems to contradict that. - How to deal with the differences between paths in different distros? Should I just roll out CFEngine manually? I thought I can just install CFEngine in anyway, and then bootstrap and it will figure everything out from there, seems like that's not the case. I hope the "hub" can tell the agents where to look for the policies? Or is the files structure just coupled together everywhere? - And honestly, is CFEngine even the right tool for use cases like mine? I don't mind tinkering a bit and working in low-level stuff, but I hate fighting with the complexity of my tools. I want a simple low-level tool with which I build my own automation, not an "out-of-the-box" corporate solution for thousands of servers. -- You received this message because you are subscribed to the Google Groups "help-cfengine" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com. ------=_Part_42729_792518029.1754236276344 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hello,<br />I'm a total newbie in CFEngine, I'm interested in learning but = I have trouble understanding how to even start, and I'm beginning to think = maybe CFEngine isn't what I need.<br /><br />Right now I have a couple of s= ervers, on which I want to deploy some services (some in Docker, some as re= gular processes), I want a solution where I can describe that declaratively= , and have a e.g. git repository with "current state of everything that's r= unning on my servers", I also want to automate stuff like setting up backup= s, updating the system, etc. It's all Linux for now, and I expect the numbe= r of servers to grow in the future.<br /><br />I previously used Ansible an= d Salt but I found those to be very opaque, complex and fragile, I wanted a= low-level solution and CFEngine really looks nice here. With ChatGPT's hel= p I even got some code that I can run to deploy Docker service and it all m= akes sense to me.<br /><br />What doesn't make sense though, is the massive= number of stuff I get in my "masterfiles" directory (I think it's called M= PF), and contradicting documentation.<br /><br />I have Alpine Linux and De= bian Linux, as hub and agent respectively. They both use different director= ies for CFEngine's files (/var/lib/cfengine vs /var/lib/cfengine3), and thi= s causes errors during bootstrap, unless I symlink, which seems hacky. In a= ddition documentation everywhere says that /var/cfengine should be used, wh= ich is not the case.<br /><br />In addition - the number of stuff in MPF ad= ds, what I think is, unnecessary complexity to my use case, ideally I'd pro= bably copy some stuff like stdlib etc. but delete the rest. I tried to star= t with a small and simple promises.cf but I failed miserably due to some is= sues with relative paths access, the failsafe.cf requested relative paths, = while the hub didn't allow me to define ACL for relative paths...<br /><br = />Anyway, I think what I really want to know is:<br />- Is there any "pract= ical" guide for CFEngine which is reasonably recent, and can guide me throu= gh building small-scale stuff from the grounds up. I'd appreciate a link.<b= r />- Do I need MPF? If I have a git repo do I just copy MPF into it? What = does MPF do for me? The very reason that I wanted to learn CFEngine is the = simplicity and transparency of what it does, MPF seems to contradict that.<= br />- How to deal with the differences between paths in different distros?= Should I just roll out CFEngine manually? I thought I can just install CFE= ngine in anyway, and then bootstrap and it will figure everything out from = there, seems like that's not the case. I hope the "hub" can tell the agents= where to look for the policies? Or is the files structure just coupled tog= ether everywhere?<br />- And honestly, is CFEngine even the right tool for = use cases like mine? I don't mind tinkering a bit and working in low-level = stuff, but I hate fighting with the complexity of my tools. I want a simple= low-level tool with which I build my own automation, not an "out-of-the-bo= x" corporate solution for thousands of servers.<br /> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;help-cfengine" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">help-= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/= help-cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com?utm_= medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d/msgid/help-= cfengine/bb9c9079-38bc-4671-9069-18ae623e6aa3n%40googlegroups.com</a>.<br /= > ------=_Part_42729_792518029.1754236276344-- ------=_Part_42728_1671617567.1754236276344--