Subject Alt Names for puppetdb

I'd like to be able to have multiple puppetdb servers that are able to answer for then namesspace of so that I can pop them behind either a simple SLB, or into DNS Round Robin. It looks like the right way to do this is to add a dnsaltnames configuration option in the [main] section of the clients puppet.conf so that when it generates it's cert with the Puppet CA, that it'll be able to answer with both it's fqdn and the CNAME, I was just wondering

a) am thinking about that right? and b) is this a really foolish way to do this?


Yes, this will work.

Just add dns_alt_names = in the [main] section and let puppet generate the appropiate certificate.

You can use multiple PuppetDB instances behind a load balancer. You just have to take care, that all instances behind the load balancer or DNS RR entry are using the same database server and database, e.g. /etc/puppetdb/conf.d/database.ini has to be identical on all machines.

Fantastic! Thanks for the response!

tfhartmann gravatar imagetfhartmann ( 2014-09-21 14:11:33 -0600 )edit

