Our configuration management is based on a multi-master puppetserver architecture.
After a new puppetserver is installed it needs SSL-certificates which contains the puppetmaster name as an DNS-ALT name in addition to the nodes hostname. This certificate is not created automatically, so the following procedure has to be performed on the new puppetmaster and the puppetca.
root@newpuppetmaster:~# grep alt /etc/puppetlabs/puppet/puppet.conf dns_alt_names = puppet.sky.rothaugane.com |
Follow our guide to regnerate a puppet certificate to let the puppetserver get its new cert.
The new puppetserver needs to be registered in Shiftleader as well. Do the following:
sl2 puppetserver create puppet1-trd2.infra.stack.it.ntnu.no StackIT sl2 user create puppet1-trd2 # Will prompt for a password. Choose a rather long one (64 characters) sl2 user add --role puppet puppet1-trd2 |
The username and password should then be added to the node-specific hiera file:
shiftleader::worker::username: 'puppet1-trd2' shiftleader::worker::password: 'PASSWORD' |
After a new puppetserver is successfully installed, remember to deploy puppet environments to it from shiftleader