Our configuration management is based on a multi-master puppetserver architecture.
Install a puppetserver
After a new puppetserver is installed it needs SSL-certificates which contains the puppetmaster name as an DNS-ALT name in addition to the nodes hostname. This certificate is not created automatically, so the following procedure has to be performed on the new puppetmaster and the puppetca.
Make sure the common DNS alt-name is configured
Verify that the DNS alt-name is configured
root@newpuppetmaster:~# grep alt /etc/puppetlabs/puppet/puppet.conf dns_alt_names = puppet.sky.rothaugane.com
Regenerate the masters certificate with the new altname included
Follow our guide to regnerate a puppet certificate to let the puppetserver get its new cert.
Shiftleader2
The new puppetserver needs to be registered in Shiftleader as well. Do the following:
sl2 puppetserver create puppet1-trd2.infra.stack.it.ntnu.no StackIT sl2 user create puppet1-trd2 # Will prompt for a password. Choose a rather long one (64 characters) sl2 user add --role puppet puppet1-trd2
The username and password should then be added to the node-specific hiera file:
shiftleader::worker::username: 'puppet1-trd2' shiftleader::worker::password: 'PASSWORD'
Deploy environments from shiftleader
After a new puppetserver is successfully installed, remember to deploy puppet environments to it from shiftleader