Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-20 Thread Patrick
On Dec 20, 2010, at 2:43 AM, Felix Frank wrote: > Sorry for the late answer, my provider had a downtime this weekend. > >>> Tough call. There is no such thing as a "transparent SSL proxy" afaik, >>> because without decrypting requests, the proxy cannot make any header >>> based decisions. >>> >

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-20 Thread Felix Frank
Sorry for the late answer, my provider had a downtime this weekend. >> Tough call. There is no such thing as a "transparent SSL proxy" afaik, >> because without decrypting requests, the proxy cannot make any header >> based decisions. >> >> This may well be a dead end then. > > Ah. See below for

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Patrick
On Dec 16, 2010, at 7:55 AM, Felix Frank wrote: > On 12/16/2010 10:28 AM, Patrick wrote: >> >> >> On Dec 16, 2010, at 1:04 AM, Brice Figureau wrote: My original error was that I didn't set: SSLProxyEngine on Now I'm just getting errors that say all requests are forbidden.

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Felix Frank
On 12/16/2010 05:06 PM, Richard Crowley wrote: >> Is it possible to have the fileserving subset of puppetmasters running >> without any SSL support? That's throwing security out of the windows of >> course, so the proxy should be able to determine (say, by IP rule?) what >> clients are allowed and

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Richard Crowley
> Is it possible to have the fileserving subset of puppetmasters running > without any SSL support? That's throwing security out of the windows of > course, so the proxy should be able to determine (say, by IP rule?) what > clients are allowed and which aren't. This seems like a job for a new file

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Felix Frank
On 12/16/2010 10:28 AM, Patrick wrote: > > > On Dec 16, 2010, at 1:04 AM, Brice Figureau wrote: >>> My original error was that I didn't set: >>> SSLProxyEngine on >>> >>> Now I'm just getting errors that say all requests are forbidden. I >>> assume this is because the puppetmaster isn't seeing t

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Patrick
On Dec 16, 2010, at 1:04 AM, Brice Figureau wrote: >> My original error was that I didn't set: >> SSLProxyEngine on >> >> Now I'm just getting errors that say all requests are forbidden. I >> assume this is because the puppetmaster isn't seeing the headers from >> apache that have the SSL infor

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Patrick
On Dec 16, 2010, at 12:45 AM, Felix Frank wrote: > On 12/15/2010 07:40 PM, Patrick wrote: >> >> In summery, both servers work, but no redirection is taking place. > > Hum, I'm not in the habit of using ProxyPass directives. I rather add > RewriteRules that include the [P] flag. > > One stupid

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Patrick
On Dec 16, 2010, at 12:45 AM, Felix Frank wrote: > On 12/15/2010 07:40 PM, Patrick wrote: >> >> On Dec 15, 2010, at 3:09 AM, Felix Frank wrote: >> >>> >>> >>> On 12/15/2010 12:04 PM, Patrick wrote: I'm looking for a way to run more than one puppetmaster on the same server under pass

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Brice Figureau
On Wed, 2010-12-15 at 20:15 -0800, Patrick wrote: > On Dec 15, 2010, at 1:48 PM, Brice Figureau wrote: > > > On 15/12/10 12:04, Patrick wrote: > >> I'm looking for a way to run more than one puppetmaster on the same > >> server under passenger. Most of the puppet CPU load is waiting for > >> the

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-16 Thread Felix Frank
On 12/15/2010 07:40 PM, Patrick wrote: > > On Dec 15, 2010, at 3:09 AM, Felix Frank wrote: > >> >> >> On 12/15/2010 12:04 PM, Patrick wrote: >>> I'm looking for a way to run more than one puppetmaster on the same >>> server under passenger. Most of the puppet CPU load is waiting for >>> the cata

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-15 Thread Patrick
On Dec 15, 2010, at 1:48 PM, Brice Figureau wrote: > On 15/12/10 12:04, Patrick wrote: >> I'm looking for a way to run more than one puppetmaster on the same >> server under passenger. Most of the puppet CPU load is waiting for >> the catalogs to compile. This also seems to be mostly what takes

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-15 Thread Brice Figureau
On 15/12/10 12:04, Patrick wrote: > I'm looking for a way to run more than one puppetmaster on the same > server under passenger. Most of the puppet CPU load is waiting for > the catalogs to compile. This also seems to be mostly what takes > large amounts of RAM. I have storedconfigs on. If you

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-15 Thread Patrick
On Dec 15, 2010, at 3:09 AM, Felix Frank wrote: > > > On 12/15/2010 12:04 PM, Patrick wrote: >> I'm looking for a way to run more than one puppetmaster on the same server >> under passenger. Most of the puppet CPU load is waiting for the catalogs to >> compile. This also seems to be mostly

Re: [Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-15 Thread Felix Frank
On 12/15/2010 12:04 PM, Patrick wrote: > I'm looking for a way to run more than one puppetmaster on the same server > under passenger. Most of the puppet CPU load is waiting for the catalogs to > compile. This also seems to be mostly what takes large amounts of RAM. I > have storedconfigs o

[Puppet Users] Separating puppetmaster file serving and catalogs

2010-12-15 Thread Patrick
I'm looking for a way to run more than one puppetmaster on the same server under passenger. Most of the puppet CPU load is waiting for the catalogs to compile. This also seems to be mostly what takes large amounts of RAM. I have storedconfigs on. I want to be able to move the fileserver to a