Ask Your Question

Subject Alt Names for puppetdb

asked 2014-09-19 13:54:25 -0600

tfhartmann gravatar image

I'd like to be able to have multiple puppetdb servers that are able to answer for then namesspace of so that I can pop them behind either a simple SLB, or into DNS Round Robin. It looks like the right way to do this is to add a dnsaltnames configuration option in the [main] section of the clients puppet.conf so that when it generates it's cert with the Puppet CA, that it'll be able to answer with both it's fqdn and the CNAME, I was just wondering

a) am thinking about that right? and b) is this a really foolish way to do this?


edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2014-09-20 17:08:48 -0600

stdietrich gravatar image

Yes, this will work.

Just add dns_alt_names = in the [main] section and let puppet generate the appropiate certificate.

You can use multiple PuppetDB instances behind a load balancer. You just have to take care, that all instances behind the load balancer or DNS RR entry are using the same database server and database, e.g. /etc/puppetdb/conf.d/database.ini has to be identical on all machines.

edit flag offensive delete link more


Fantastic! Thanks for the response!

tfhartmann gravatar imagetfhartmann ( 2014-09-21 14:11:33 -0600 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2014-09-19 13:54:25 -0600

Seen: 324 times

Last updated: Sep 19 '14