Ask Your Question

How do I get Puppet Master to run a manifest against a Puppet agent node?

asked 2016-01-25 19:28:22 -0600

Conventional gravatar image

updated 2016-01-25 19:34:05 -0600

I am trying to run a Puppet manifest for the first time on two new servers. But I keep getting errors.

I recently set up two CentOS v7 servers. I configured them to have have passwordless SSH between them. Ports 22, 443, 8140, and 6160 are all open between the servers. I have Puppet Master 3.8 on one server. I have Puppet Agent 3.8 on another server. I am using the open source of Puppet.

The OpenSSL that is installed is from February 2013. I'd like to not upgrade OpenSSL. I did an nslookup on the IP addresses of both servers. Both returned the correct DNS names. I have /etc/hosts files on both servers with entries of the other server.

On the Puppet Agent server, I have a Puppet.conf file with an entry like this in the master section:

server = FQDNOfPuppetMaster

On the Puppet Agent server, I have a Puppet.conf file with an entry like this in the agent section:

server = FQDNOfPuppetAgent

On the Puppet Agent server I requested a certificate. I signed it on the Puppet Master server. Manifests won't run.

Here is what I get when I run my manifest (puppet agent -t newManifest.pp --server=x.x.x.x) to compile it into the catalog on the Puppet Master server:

Warning: Unable to fetch my node definition, but the agent run will continue:
Warning: SSL_connect returned=1 errno=0 state=SSLv2/v3 read sever hello A: unknown protocol
Info: Retrieving plugin facts
Error: /File[/var/lib/puppet/facts.d]: Failed to generate additional resources using 'eval_generate : SSL_Connect returned=1 errno=0 state=SSLv2/v3 read server hello A: unknown protocol

I ran the puppet agent command as root. x.x.x.x was the IP address of the Puppet Agent server.

There is no evidence that it ran on the Puppet Agent server. I run puppet agent -t verbose on the Puppet Agent server.

I can ping each server from the other. I can SSH to each server from the other. What am I doing wrong?

edit retag flag offensive close merge delete

1 answer

Sort by » oldest newest most voted

answered 2016-06-17 00:48:21 -0600

cm01 gravatar image

This is an old qn, but just in case anyone else drops by, see

Basically normal Puppet is a pull mechanism, not a push one ie the client node contacts the master, not the other way around.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2016-01-25 19:28:22 -0600

Seen: 293 times

Last updated: Jun 17 '16