cb9f8870bfda20fcc8329b16a03d00a6e76f936b
Catalog compilation moved to the k8s puppetserver compilers, which sign host certificates against the terraform-managed `sshca` mount. Clients only trust the legacy `ssh-host-signer` CA, so every re-signed node (ausyd1nxvm2120 already) presents a certificate nothing accepts, and knownhosts emits no plain host-key fallback. - Add a second `@cert-authority *` entry for the `sshca` public key to `profiles::ssh::knownhosts::lines`. - Keep the legacy entry untouched so legacy-signed hosts still verify. Reviewed-on: #530 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
Description
production puppet-control repository
Languages
Puppet
65.7%
HTML
28.5%
Ruby
5.8%