class krb5hostkeytab { file { "/etc/krb5.keytab": mode => "0600", owner => 'root', group => 'root', source => "puppet:///modules/krb5hostkeytab/${trusted[certname]}.keytab", } service { 'rpc-gssd.service': provider => systemd, ensure => running, enable => true, subscribe => File['/etc/krb5.keytab'], } }