From 6c880d979418e229969a00b44415807bf0739ac9 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Fri, 9 Oct 2026 21:51:43 +1100 Subject: [PATCH] Add consul server federation SANs to consul server certs (#547) WAN federation through mesh gateways makes Consul verify server certs against `server..consul` and `.server..consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified. - add `server.-.consul` to consul server alt_names - add `.server.-.consul` to consul server alt_names Reviewed-on: https://git.unkin.net/unkin/puppet-prod/pulls/547 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- hieradata/roles/infra/storage/consul.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hieradata/roles/infra/storage/consul.yaml b/hieradata/roles/infra/storage/consul.yaml index 8741c43..cac2fe4 100644 --- a/hieradata/roles/infra/storage/consul.yaml +++ b/hieradata/roles/infra/storage/consul.yaml @@ -31,6 +31,8 @@ profiles::pki::vault::alt_names: - consul.service.consul - "consul.service.%{facts.country}-%{facts.region}.consul" - consul + - "server.%{facts.country}-%{facts.region}.consul" + - "%{facts.networking.fqdn}.server.%{facts.country}-%{facts.region}.consul" # manage a simple nginx reverse proxy profiles::nginx::simpleproxy::nginx_vhost: 'consul.service.consul'