Add consul server federation SANs to consul server certs (#547)
WAN federation through mesh gateways makes Consul verify server certs against `server.<dc>.consul` and `<node_name>.server.<dc>.consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified. - add `server.<country>-<region>.consul` to consul server alt_names - add `<fqdn>.server.<country>-<region>.consul` to consul server alt_names Reviewed-on: #547 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #547.
This commit is contained in:
@@ -31,6 +31,8 @@ profiles::pki::vault::alt_names:
|
||||
- consul.service.consul
|
||||
- "consul.service.%{facts.country}-%{facts.region}.consul"
|
||||
- consul
|
||||
- "server.%{facts.country}-%{facts.region}.consul"
|
||||
- "%{facts.networking.fqdn}.server.%{facts.country}-%{facts.region}.consul"
|
||||
|
||||
# manage a simple nginx reverse proxy
|
||||
profiles::nginx::simpleproxy::nginx_vhost: 'consul.service.consul'
|
||||
|
||||
Reference in New Issue
Block a user