On Monday, June 27, 2016 at 2:48:33 AM UTC-7, Dominic Cleal wrote:
>
> On 27/06/16 09:15, Thomas Cheng wrote: 
> > 
> > 
> > On Monday, June 27, 2016 at 12:36:29 AM UTC-7, Dominic Cleal wrote: 
> > 
> >     On 23/06/16 20:15, Thomas Cheng wrote: 
> >     > I got the following errors in forman-proxy's proxy.log file, after 
> I 
> >     > turned on debugging, Any one know what this error means? Thanks. 
> >     > 
> >     > # Logfile created on Wed Jun 22 17:15:26 -0700 2016 by 
> >     logger.rb/1.2.6 
> >     > E, [2016-06-22T17:17:38.836692 #58935] ERROR -- : Failed to list 
> >     puppet 
> >     > environments: Connection refused - connect(2) 
> >     > E, [2016-06-22T17:17:48.592771 #58935] ERROR -- : Failed to list 
> >     puppet 
> >     > environments: Connection refused - connect(2) 
> > 
> >     The smart proxy connects to the Puppet master to retrieve a list of 
> >     environments, this suggests that the master isn't running (usually 
> >     under 
> >     Apache). 
> > 
> >     Also check that :puppet_url is set correctly in 
> >     /etc/foreman-proxy/settings.d/puppet.yml, see 
> >     https://theforeman.org/manuals/1.11/index.html#4.3.6Puppet 
> >     <https://theforeman.org/manuals/1.11/index.html#4.3.6Puppet>. You 
> >     should 
> >     be able to telnet to the same host/port specified in the config. 
> > 
> > I see. I checked the setup, and it points to a Load-balanced URL: 
> > https://balanced_foreman.example.com/. so here is my question inviting 
> > for recommendations / best practice: 
> > 
> > We have a Foreman cluster (more than an all-in-one installation) to 
> > handle thousands of nodes. And so, Foreman (REST API, Reports, ENC, 
> > Web), Foreman-proxy (with proxyed puppet master function), and puppet 
> > masters are load balanced: 
> > 
> > load balanced Foreman (ports 80,443):  balanced_foreman.example.com 
> > load balanced Foreman-proxy (8443) : balanced_proxy.example.com 
> > load balanced puppet master (8140): balanced_pm.example.com 
> > 
> > And loads/requests are distributed equally to 3 different 'worker' 
> > nodes:  nodeA, nodeB, nodeC. each nodes runs all three: Foreman (80 & 
> > 443), Foreman-proxy (8443), and puppet master (8140). 
> > 
> > Then on each node, say, nodeA, when a service need to talk with another, 
> > should it use load-balanced form, or better it  should directly use the 
> > service runs on the same node? 
> > 
> > i.e,  when nodeA' foreman-proxy needs to get a list of puppet 
> > environments, should the value ':puppet_url' better to be set as: 
> >    https://nodeA.example.com:8140,  or https://balanced_pm.example.com? 
> > 
> > The first one ( https://nodeA.example.com:8140) may seems more 
> efficient 
> > (it doesn't need to go to load director, and potentially distributed 
> > back to the same machine requests come from), also the debugging is 
> > easier, don't need to check logs on three servers should error pops up; 
> > 
> > while the second solution mean more resilient, with the price of 
> complexity. 
> > 
> > What's your suggestions and how's the popular choices here?  Many 
> thanks. 
>
> I don't recommend anything in particular, I doubt it matters much. 
> Either should work provided the SSL certificates in use match the 
> hostname you're connecting to (i.e. if connecting to the node directly, 
> the sAN list must contain the node hostname). 
>  
>
Sure. Thanks for your input. 

> -- 
> Dominic Cleal 
> [email protected] <javascript:> 
>

-- 
You received this message because you are subscribed to the Google Groups 
"Foreman users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/group/foreman-users.
For more options, visit https://groups.google.com/d/optout.

Reply via email to