Compare commits

...

3 Commits

Author SHA1 Message Date
unkin-agent 64356b5e88 consul: keep VM servers in syd1 client join list
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
2026-10-09 23:06:02 +11:00
unkin-agent 412771a766 consul: point syd1 clients at k8s consul servers
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was canceled
2026-10-09 23:01:45 +11:00
unkin-agent 6c880d9794 Add consul server federation SANs to consul server certs (#547)
WAN federation through mesh gateways makes Consul verify server certs against `server.<dc>.consul` and `<node_name>.server.<dc>.consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified.

- add `server.<country>-<region>.consul` to consul server alt_names
- add `<fqdn>.server.<country>-<region>.consul` to consul server alt_names

Reviewed-on: #547
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 21:51:43 +11:00
2 changed files with 9 additions and 1 deletions
+7 -1
View File
@@ -8,8 +8,14 @@ profiles_dns_upstream_forwarder_consul:
profiles_dns_upstream_forwarder_k8s:
- 198.18.19.20
profiles::consul::client::members_lookup: false
# static: k8s-compiled hosts can't see the servers in PuppetDB; update when servers change
# static list: hosts compiled in k8s can't look up the servers in PuppetDB.
# VM names stay until the VM servers are retired.
profiles::consul::client::consul_servers:
- 198.18.200.11
- 198.18.200.12
- 198.18.200.13
- 198.18.200.14
- 198.18.200.15
- ausyd1nxvm2005.main.unkin.net
- ausyd1nxvm2006.main.unkin.net
- ausyd1nxvm2007.main.unkin.net
@@ -31,6 +31,8 @@ profiles::pki::vault::alt_names:
- consul.service.consul
- "consul.service.%{facts.country}-%{facts.region}.consul"
- consul
- "server.%{facts.country}-%{facts.region}.consul"
- "%{facts.networking.fqdn}.server.%{facts.country}-%{facts.region}.consul"
# manage a simple nginx reverse proxy
profiles::nginx::simpleproxy::nginx_vhost: 'consul.service.consul'