Ask Your Question
0

Subject Alt Names for puppetdb

asked 2014-09-19 13:54:25 -0600

tfhartmann gravatar image

I'd like to be able to have multiple puppetdb servers that are able to answer for then namesspace of puppetdb.example.com so that I can pop them behind either a simple SLB, or into DNS Round Robin. It looks like the right way to do this is to add a dnsaltnames configuration option in the [main] section of the clients puppet.conf so that when it generates it's cert with the Puppet CA, that it'll be able to answer with both it's fqdn and the puppetdb.example.com CNAME, I was just wondering

a) am thinking about that right? and b) is this a really foolish way to do this?

Thanks!

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
1

answered 2014-09-20 17:08:48 -0600

stdietrich gravatar image

Yes, this will work.

Just add dns_alt_names = puppetdb.example.com in the [main] section and let puppet generate the appropiate certificate.

You can use multiple PuppetDB instances behind a load balancer. You just have to take care, that all instances behind the load balancer or DNS RR entry are using the same database server and database, e.g. /etc/puppetdb/conf.d/database.ini has to be identical on all machines.

edit flag offensive delete link more

Comments

Fantastic! Thanks for the response!

tfhartmann gravatar imagetfhartmann ( 2014-09-21 14:11:33 -0600 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2014-09-19 13:54:25 -0600

Seen: 225 times

Last updated: Sep 19 '14