Our configuration management is based on a multi-master puppetserver architecture.

Install a puppetserver

After a new puppetserver is installed it needs SSL-certificates which contains the puppetmaster name as an DNS-ALT name in addition to the nodes hostname. This certificate is not created automatically, so the following procedure has to be performed on the new puppetmaster and the puppetca.

Make sure the common DNS alt-name is configured

Verify that the DNS alt-name is configured
root@newpuppetmaster:~# grep alt /etc/puppetlabs/puppet/puppet.conf 
dns_alt_names = puppet.sky.rothaugane.com

Regenerate the masters certificate with the new altname included

Follow our guide to regnerate a puppet certificate to let the puppetserver get its new cert.

Shiftleader2

The new puppetserver needs to be registered in Shiftleader as well. Do the following:

sl2 puppetserver create puppet1-trd2.infra.stack.it.ntnu.no StackIT
sl2 user create puppet1-trd2 # Will prompt for a password. Choose a rather long one (64 characters) 
sl2 user add --role puppet puppet1-trd2

The username and password should then be added to the node-specific hiera file:

shiftleader::worker::username: 'puppet1-trd2'
shiftleader::worker::password: 'PASSWORD'


Deploy environments from shiftleader

After a new puppetserver is successfully installed, remember to deploy puppet environments to it from shiftleader

  • No labels