Skip to content

WIP: feat(azure): add Fleet module with authenticated package repo support - #10

Open
zyoutz wants to merge 5 commits into
mainfrom
feature/azure-fleet
Open

zyoutz wants to merge 5 commits into
mainfrom
feature/azure-fleet

Conversation

@zyoutz

@zyoutz zyoutz commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • New Azure Fleet module (modules/azure/fleet/) — deploys Corelight Fleet Manager on a single Azure Linux VM behind a Standard public load balancer with dual-port forwarding (443 web UI, 1443 sensor API), conditional NSG, and optional Azure DNS integration
  • New example (examples/azure/fleet/) — reference deployment creating resource group, subnet, and fleet module
  • Updated shared fleet cloud-init config (modules/_shared/config/fleet/) — adds corelight_package_repo_token variable to support the new authenticated Corelight package repository at pkgrepos.corelight.cloud. Falls back to legacy packages.corelight.com when token is not provided
  • Updated AWS fleet module (modules/aws/fleet/) — propagates corelight_package_repo_token through to the shared config

What needs testing

Azure Fleet module

  • Deploy the module in Azure with a valid corelight_package_repo_token, certificate, and license
  • Verify Fleet VM boots and cloud-init installs corelight-fleet from the authenticated repo
  • Verify the LB is reachable on port 443 (web UI) and port 1443 (sensor API)
  • Verify DNS record creation when dns_zone_name is provided
  • Verify BYO NSG works when nsg_id is provided
  • Verify SSH access works when admin_cidr_blocks is set
  • Test with a custom image via fleet_image_id

AWS Fleet module (auth token regression)

  • Deploy the existing AWS fleet module with corelight_package_repo_token set and verify Fleet installs from the new authenticated repo
  • Deploy without the token to verify the legacy packages.corelight.com fallback still works

Shared config

  • Verify Debian (Ubuntu) path: GPG key import, sources list, auth.conf setup
  • Verify RHEL path: yum repo file with embedded token

Unit tests

All 30 tests pass:

  • modules/azure/fleet/ — 10 tests
  • modules/aws/fleet/ — 13 tests
  • modules/_shared/config/fleet/ — 7 tests

🤖 Generated with Claude Code

Zac Youtz and others added 5 commits September 17, 2026 14:22
…ted package repo

Add new Azure Fleet module (modules/azure/fleet/) with:
- Single Linux VM behind a Standard public load balancer
- Dual-port forwarding (443 web UI, 1443 sensor API)
- Conditional NSG with BYO pattern
- Optional Azure DNS integration
- 10 unit tests

Add example deployment at examples/azure/fleet/.

Update shared fleet cloud-init config (modules/_shared/config/fleet/) to
support the new authenticated Corelight package repository at
pkgrepos.corelight.cloud via corelight_package_repo_token variable.
Falls back to legacy public repo when token is not provided.

Propagate corelight_package_repo_token through both AWS and Azure
fleet modules.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…removed)

The old packages.corelight.com public repo no longer exists. Remove the
fallback branches from cloud-init and make the token a required variable
across all fleet modules.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Both fleet-standalone and fleet-and-sensor-single examples were missing
the now-required corelight_package_repo_token variable.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant