Add consul server federation SANs to consul server certs (#547)

WAN federation through mesh gateways makes Consul verify server certs against `server.<dc>.consul` and `<node_name>.server.<dc>.consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified.

- add `server.<country>-<region>.consul` to consul server alt_names
- add `<fqdn>.server.<country>-<region>.consul` to consul server alt_names

Reviewed-on: #547
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #547.
This commit is contained in:
2026-10-09 21:51:43 +11:00
committed by BenVincent
parent 2e95cd00d7
commit 6c880d9794
@@ -31,6 +31,8 @@ profiles::pki::vault::alt_names:
- consul.service.consul
- "consul.service.%{facts.country}-%{facts.region}.consul"
- consul
- "server.%{facts.country}-%{facts.region}.consul"
- "%{facts.networking.fqdn}.server.%{facts.country}-%{facts.region}.consul"
# manage a simple nginx reverse proxy
profiles::nginx::simpleproxy::nginx_vhost: 'consul.service.consul'