Skip to content

Installation of 'puppetmaster' package prevents Exec[Certificate_Check] from ever executing. #99

Description

@diranged

The Exec[Certificate_Check] resource requires File[/etc/puppet/puppet.conf]. This file resource though requires Package[puppetmaster]. The problem with this flow is that the instant the Package[puppetmaster] is installed, it creates any missing SSL files on its own. When it does this, the Exec[Certificate_Check] code sees the file in-place and never executes.

The net result here is that the certificate is never re-created with the dns_alt_names settings. My short-term hack is to install puppetmaster before we ever execute Puppet on our masters, then shut the service down and destroy the /var/lib/puppet/ssl directory. This is a hack though. There should be a cleaner fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions