Files
puppet-prod/hieradata/roles/infra
unkin-agent 6c880d9794 Add consul server federation SANs to consul server certs (#547)
WAN federation through mesh gateways makes Consul verify server certs against `server.<dc>.consul` and `<node_name>.server.<dc>.consul`. Node names are FQDNs, so each server needs its exact SAN. This adds the SANs ahead of Consul server TLS, which a stacked follow-up enables once the reissued certs are verified.

- add `server.<country>-<region>.consul` to consul server alt_names
- add `<fqdn>.server.<country>-<region>.consul` to consul server alt_names

Reviewed-on: #547
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-09 21:51:43 +11:00
..
2025-05-21 19:58:12 +10:00
2025-07-05 15:51:28 +10:00
2026-04-06 22:46:40 +10:00
2024-08-31 23:00:58 +10:00
2024-06-02 19:23:39 +10:00
2024-10-27 13:26:07 +11:00
2023-11-17 23:12:37 +11:00
2024-08-25 02:14:35 +10:00
2024-06-19 22:36:04 +10:00