context
[SEE IT ON YOUR DATA]
Puppet logodevelopment

Context + Puppet

Transform Puppet infrastructure intelligence into searchable configuration knowledge with an enterprise-grade knowledge graph

Puppet is the infrastructure automation platform where operations teams define the desired state of their entire infrastructure as code -- server configurations, package installations, service definitions, file permissions, and security policies. Over time, Puppet codebases accumulate a deep repository of infrastructure intelligence: why specific configuration parameters were chosen, how modules evolved to handle different operating systems and environments, which node classifications reflect production topology, and how Hiera data hierarchies encode environment-specific overrides. But this knowledge is scattered across module repositories, Hiera data files, node classifiers, and Puppet Enterprise console reports, disconnected from the Jira tickets that drove configuration changes, the Confluence runbooks documenting infrastructure standards, and the Slack channels where infrastructure decisions were debated.

Context connects to your Puppet Enterprise instance and associated code repositories to extract the organizational knowledge embedded in manifests, modules, Hiera data, node classifications, report histories, and RBAC configurations. Using permission-aware indexing that respects your Puppet Enterprise role-based access controls and node group permissions, Context builds a knowledge graph that maps relationships between modules, node configurations, infrastructure components, teams, and the broader context from your entire tool stack.

Unlike cloud-based search tools that require your infrastructure configuration data to be processed externally, Context deploys entirely on your network -- on-premise, in your VPC, or in air-gapped environments. Your Puppet manifests, node classifications, and Hiera data never leave your control. For defense contractors managing classified server fleets, aerospace companies operating safety-critical ground infrastructure, and financial institutions governing regulated server environments, infrastructure configuration data reveals system topology, security hardening decisions, and compliance posture. Context ensures this intelligence remains within your security boundary while making it searchable and actionable. Every answer is backed by citations to specific Puppet modules, node reports, or Hiera configurations, maintaining full traceability.

Key Capabilities

  • 01Permission-aware indexing of Puppet Enterprise node groups, manifests, modules, Hiera data, and report histories that respects RBAC and node group-level access controls
  • 02Module dependency mapping that builds a searchable graph of which modules depend on which other modules, enabling safe impact assessment before module upgrades or deprecations
  • 03Node configuration knowledge extraction that captures the relationship between node classifications, Hiera data overrides, and the resulting desired state for each managed node
  • 04Configuration drift and compliance reporting that indexes Puppet report data alongside Jira change tickets and Confluence compliance documentation for auditable configuration governance
  • 05Cross-tool infrastructure correlation that links Puppet manifests to GitHub source repositories, Jira change requests, ServiceNow change records, and Confluence infrastructure documentation automatically
  • 06Hiera data hierarchy analysis that makes environment-specific configuration overrides searchable and traceable to the business requirements that drove them

Use Cases

Infrastructure Configuration Impact Analysis

Before modifying a shared Puppet module or changing a Hiera data value, engineers need to understand which nodes will be affected and what the downstream impact will be. Context maps the relationships between Puppet modules, node classifications, Hiera data hierarchies, and the services running on managed nodes. Engineers can ask "which production nodes use the apache module and what Hiera overrides do they have?" and get citation-backed answers linked to specific node groups, Hiera configurations, and the Confluence documentation for affected services.

Compliance Evidence and Configuration Auditing

Regulated industries require evidence that server configurations comply with approved security baselines such as CIS Benchmarks or STIG requirements. Context indexes Puppet Enterprise report data showing configuration enforcement status alongside the Jira tickets authorizing changes and the Confluence pages defining compliance requirements. Auditors can query "which servers failed their CIS hardening compliance checks in the last 30 days?" and receive an auditable answer with citations to Puppet reports, change authorization records, and compliance standards.

Infrastructure Knowledge Transfer

Puppet codebases often contain years of infrastructure decisions encoded in manifests and Hiera data, but the reasoning behind those decisions lives in team members' heads. Context connects Puppet module documentation and configuration choices to the Jira tickets that drove the changes, the GitHub pull requests where they were reviewed, and the Slack discussions where alternatives were debated. New team members can ask "why is the PostgreSQL max_connections set to 500 on the analytics nodes?" and receive the complete decision history with citations.

Module Standardization and Reuse

Large organizations often have multiple teams writing similar Puppet modules for common infrastructure patterns. Context builds a searchable knowledge graph of all Puppet modules, classes, and defined types across the organization. Platform teams can identify module duplication, promote standardized modules, and answer questions like "do we have an existing module for configuring Vault agents?" with citation-backed results pointing to existing modules and their maintainers.

How It Works

SOURCEPuppetAnsibleTerraformGitHubPROCESSINGContext EnginePROCESSINGKnowledge GraphOUTPUTAnswers

Security & Compliance

SOC 2 Type IISOC 2 Type IIGDPRGDPRHIPAAHIPAAISO 27001ISO 27001

Deployment Options

DEPLOYMENT ARCHITECTURE

YOUR INFRASTRUCTUREOn-PremiseK3s / K8s / Bare MetalAPI ServerKnowledge GraphLLM (Ollama)PostgreSQLYour VPCAWS / Azure / GCPEKS ClusterKnowledge GraphKubeAI (GPU)S3 / BlobKARPENTER: GPU SCALE-TO-ZEROAir-GappedNo Internet RequiredAPI ServerKnowledge GraphOllama / MLXLocal StorageYOUR DATA NEVER LEAVES YOUR INFRASTRUCTURE

Frequently Asked Questions

How does Context connect to Puppet?

Context integrates with Puppet Enterprise through the platform's API using a dedicated RBAC user token with read-only permissions. Once configured, Context indexes node group configurations, classification rules, report histories, and fact data. Puppet module source code is indexed through Context's GitHub or GitLab integration. The connections are read-only -- Context never modifies your Puppet Enterprise configurations, node classifications, or modules. All processing happens on your infrastructure.

Does Context have access to Puppet secrets or sensitive data?

No. Context indexes Puppet manifests, module structures, Hiera key names, and node configurations -- never encrypted eyaml values, certificate private keys, or sensitive parameter data. Context captures the knowledge about what your infrastructure configuration does and why, not the secrets it manages. Sensitive Hiera values are excluded from indexing while key names remain searchable for discoverability.

Can Context work with Puppet in air-gapped environments?

Yes. Context deploys entirely on your infrastructure with no external dependencies. For organizations operating air-gapped infrastructure under ITAR, CMMC, or classified program requirements, Context ensures that Puppet manifests, node classifications, and infrastructure topology data never leave your controlled environment. The on-premise deployment model keeps sensitive configuration intelligence within your security boundary.

How does Context handle Puppet Enterprise RBAC?

Context respects Puppet Enterprise's role-based access control model. When users search through Context, they only see results from node groups, reports, and configurations they would have access to in Puppet Enterprise. This permission-aware indexing ensures that sensitive infrastructure configuration details for restricted environments are never exposed to unauthorized users in search results.

Which Puppet versions does Context support?

Context works with Puppet Enterprise 2019.x and later versions that provide the modern API endpoints. For organizations using open source Puppet Server without Puppet Enterprise, Context can index Puppet module repositories through the GitHub or GitLab integration and PuppetDB data through its API. The Enterprise integration provides the richest experience with node group management, RBAC, and report history.

Setup Overview

Connecting Puppet to Context requires Puppet Enterprise administrator access and typically takes around 20 minutes. The process involves creating a dedicated RBAC user with read-only API access, selecting which node groups and environments to index, and mapping Puppet Enterprise roles to Context access controls. Puppet module repositories are indexed through Context's GitHub or GitLab integration. Context handles the rest -- indexing begins automatically and the knowledge graph starts building within minutes. No changes to your Puppet Enterprise configuration or node management workflows are required.

Ready to connect Puppet?

See Context + Puppet in action with a 30-minute technical walkthrough tailored to your environment.

BOOK A DEMO