Meta tags:
description=
Warning
Chef Backend is deprecated and no longer under active development. Contact your Chef account representative for information about migrating to Chef Automate HA.;
Headings (most frequently used words):
backend, frontend, chef, step, cluster, server, infra, nodes, and, communication, from, configure, the, group, network, services, requirements, install, on, between, inbound, to, high, availability, overview, recommended, topology, installation, security, considerations, rb, options, ctl, key, differences, standalone, port, create, shared, credentials, remaining, generate, configuration, first, adding, more, upgrading, machines, configuring, members, different, networks, securing, secrets, software, versions, hardware, load, balancer, peer,
Text of the page (most frequently used words):
chef (276), the (237), backend (151), and (90), #server (90), #cluster (78), frontend (69), infra (63), nodes (53), overview (49), node (48), install (45), postgresql (36), for (35), with (34), all (33), configure (31), automate (31), ctl (30), version (30), builder (30), from (29), deployment (28), aws (27), group (26), step (26), this (26), create (22), you (22), etc (22), upgrade (21), about (21), habitat (20), communication (19), network (19), requirements (19), will (19), config (19), user (19), packages (18), api (18), supermarket (18), are (17), manage (17), settings (17), that (17), services (16), configuration (16), following (16), run (16), users (16), prem (16), file (14), elasticsearch (14), package (14), opscode (14), management (14), workstation (14), reference (14), between (13), availability (13), community (13), system (13), database (13), data (13), not (12), members (12), key (12), high (12), must (12), each (12), md5_auth_cidr_addresses (12), restore (12), license (12), 360 (12), managed (12), secrets (11), more (11), first (11), should (11), recovery (11), backup (11), security (10), load (10), files (10), set (10), example (10), samehost (10), samenet (10), md5 (10), private (10), new (10), cloud (10), compliance (10), client (10), platform (10), effortless (10), saas (10), started (10), opensearch (10), other (9), use (9), line (9), log (9), json (9), access (9), service (9), using (9), 192 (9), 168 (9), add (9), any (8), versions (8), different (8), can (8), command (8), host (8), opt (8), chef_pgsql (8), local (8), copy (8), upgrades (8), update (8), resources (8), prerequisites (8), origin (8), disaster (8), desktop (8), guide (8), certificates (8), iam (8), software (7), page (7), generate (7), credentials (7), installation (7), balancer (7), your (7), available (7), leader (7), root (7), etcd (7), var (7), authentication (7), subnet (7), servers (7), migration (7), sudo (7), external (7), download (7), see (6), policy (6), networks (6), inbound (6), standalone (6), feedback (6), value (6), which (6), conf (6), password (6), then (6), running (6), filename (6), may (6), pem (6), core (6), home (6), net (6), content (6), tcp (6), premises (6), cookbooks (6), audit (6), migrate (6), inspec (6), style (6), cookstyle (6), supported (6), troubleshooting (6), logs (6), get (6), integrations (6), dashboard (6), applications (6), certificate (6), enterprise (6), used (5), one (5), terms (5), licensing (5), options (5), remaining (5), shared (5), support (5), start (5), information (5), address (5), publish_address (5), default (5), runs (5), only (5), number (5), them (5), list (5), process (5), disk (5), after (5), setting (5), hostssl (5), replication (5), replicator (5), pg_hba (5), connect (5), has (5), join (5), bootstrap (5), three (5), single (5), downloads (5), storage (5), architecture (5), setup (5), progress (4), trademarks (4), its (4), configuring (4), adding (4), peer (4), hardware (4), back (4), during (4), reconfigure (4), without (4), these (4), have (4), gen (4), leaderl (4), account (4), happens (4), clear (4), active (4), need (4), values (4), two (4), such (4), frontends (4), follow (4), rsa (4), generated (4), location (4), option (4), path (4), note (4), same (4), fe1 (4), pid (4), 59m (4), time (4), clusters (4), when (4), console (4), azure (4), send (4), uninstall (4), organizations (4), groups (4), roles (4), saml (4), ldap (4), resource (4), packs (4), profiles (4), apis (4), monitor (4), quick (4), deprecations (4), cops (4), v26 (4), firewalls (4), ports (4), authorization (4), origins (4), profile (4), minio (4), cookbook (4), application (4), enrollment (4), infrastructure (4), getting (4), courier (4), tokens (4), jobs (4), app (4), integration (4), amazon (4), a2ha (4), platforms (4), edition (4), product (3), names (3), their (3), securing (3), considerations (3), upgrading (3), machines (3), port (3), recommended (3), topology (3), differences (3), table (3), contents (3), document (3), github (3), help (3), individual (3), name (3), fqdn (3), modify (3), feature (3), flags (3), into (3), been (3), components (3), uses (3), automatically (3), monitoring (3), encryption (3), but (3), view (3), case (3), where (3), state (3), important (3), backends (3), allow (3), entries (3), added (3), existing (3), also (3), specify (3), systems (3), cidr (3), usage (3), copied (3), level (3), validator (3), user_name (3), association_user (3), non (3), space (3), 4thcafe (3), janedoe (3), administrator (3), touch (3), scp (3), online (3), status (3), directory (3), remove (3), public (3), n_in_cidr (3), 1_in_cidr (3), box (3), external_ip_address_of_this_box (3), bootstrapping (3), place (3), across (3), tiered (3), verify (3), session (3), virtual (3), physical (3), scale (3), search (3), provides (3), comprised (3), herein (2), corporation (2), subsidiaries (2), affiliates (2), rights (2), reserved (2), respective (2), owners (2), does (2), 2026 (2), improve (2), contact (2), still (2), was (2), tool (2), documentation (2), end (2), ipv4 (2), wish (2), sensitive (2), control (2), most (2), please (2), changing (2), attempt (2), out (2), included (2), full (2), owner (2), under (2), listed (2), 0600 (2), requires (2), passwords (2), initial (2), because (2), unauthenticated (2), communicate (2), provided (2), contain (2), would (2), being (2), over (2), array (2), exist (2), saved (2), safe (2), save (2), specified (2), absolute (2), begin (2), characters (2), fourth (2), cafe (2), inc (2), lower (2), org (2), organization (2), bootstrapped (2), configured (2), fe_name (2), via (2), current (2), additional (2), follower (2), total (2), green (2), debian (2), ubuntu (2), dpkg (2), path_to_deb (2), red (2), hat (2), centos (2), yum (2), path_to_rpm (2), ssh (2), balanced (2), 9200 (2), 5432 (2), 2379 (2), type (2), warning (2), ssd (2), premium (2), microsoft (2), ebs (2), optimized (2), gp2 (2), ram (2), cores (2), bound (2), good (2), multiple (2), handle (2), requests (2), topic (2), longer (2), environments (2), bags (2), clients (2), legacy (2), remediation (2), release (2), notes (2), share (2), what (2), scaffolding (2), variables (2), pattern (2), attributehelper (2), attributedefault (2), useplatformhelpers (2), unnecessaryplatformcasestatement (2), unnecessaryoscheck (2), trueclassfalseclassresourceproperties (2), simplifyplatformmajorversioncheck (2), overlycomplexsupportsdependsmetadata (2), negatingonlyif (2), includerecipewithparentheses (2), immediatenotificationtiming (2), filemode (2), defaultcopyrightcomments (2), copyrightcommentformat (2), commentsentencespacing (2), commentformat (2), chefwhaaat (2), attributekeys (2), invalidlicensestring (2), insecurecookbookurl (2), includeresourceexamples (2), includeresourcedescriptions (2), includepropertydescriptions (2), emptymetadatafield (2), defaultmetadatamaintainer (2), sharing (2), sshprivatekey (2), unlessdefinedrequire (2), requirenethttps (2), legacypowershelloutmethods (2), gemspecrequirerubygems (2), gemspeclicense (2), ruby (2), usecreateifmissing (2), unnecessarynameproperty (2), unnecessarydesiredstate (2), suggestsmetadata (2), stringpropertywithnildefault (2), sensitivepropertyinresource (2), resourcewithnothingaction (2), replacesmetadata (2), recipemetadata (2), providesmetadata (2), propertywithrequiredanddefault (2), propertysplatregex (2), ohaiattributetostring (2), namepropertyisrequired (2), multipleplatformchecks (2), longdescriptionmetadata (2), groupingmetadata (2), doublecompiletime (2), customresourcewithallowedactions (2), conflictsmetadata (2), attributemetadata (2), aptrepositorynotifiesaptupdate (2), aptrepositorydistributiondefault (2), redundantcode (2), zipfileresource (2), windowszipfileusage (2), windowsscresource (2), windowsregistryuac (2), whyrunsupportedtrue (2), useszypperrepo (2), userequirerelative (2), usemultipackageinstalls (2), usecheflanguagesystemdhelper (2), usecheflanguageenvhelpers (2), usecheflanguagecloudhelpers (2), usebuildessentialresource (2), unnecessarymixlibshelloutrequire (2), unnecessarydependschef15 (2), unnecessarydependschef14 (2), sysctlparamresource (2), simplifyaptppasetup (2), shellouttochocolatey (2), shellouthelper (2), sevenziparchiveresource (2), setorreturninresources (2), respondtoresourcename (2), respondtoprovides (2), respondtoinmetadata (2), respondtocompiletime (2), resourcenamefrominitialize (2), resourceforcingcompiletime (2), providesfrominitialize (2), propertywithnameattribute (2), powershellscriptexpandarchive (2), powershellinstallwindowsfeature (2), powershellinstallpackage (2), powershellguardinterpreter (2), osxconfigprofileresource (2), opensslx509resource (2), opensslrsakeyresource (2), noderolesinclude (2), nodeinitpackage (2), minitesthandlerusage (2), macosxuserdefaults (2), libarchivefileresource (2), legacyberksfilesource (2), includingwindowsdefaultrecipe (2), includingohaidefaultrecipe (2), includingmixinshelloutinresources (2), includingaptdefaultrecipe (2), ifprovidesdefaultaction (2), foodcriticcomments (2), executetzutil (2), executesysctl (2), executesleep (2), executescexe (2), executeaptupdate (2), emptyresourceinitializemethod (2), dslincludeinresource (2), dependsonzyppercookbook (2), dependsonwindowsfirewallcookbook (2), dependsontimezonelwrpcookbook (2), dependsonopensslcookbook (2), dependsonlocalecookbook (2), dependsonkernelmodulecookbook (2), dependsonchocolateycookbooks (2), dependsonchefvaultcookbook (2), definitions (2), defineschefspecmatchers (2), defaultactionfrominitialize (2), declareactionclass (2), databaghelpers (2), customresourcewithattributes (2), cronmanageresource (2), crondfileortemplate (2), conditionalusingtest (2), classevalactionclass (2), chefgemnokogiri (2), allowedactionsfrominitialize (2), actionmethodinresource (2), modernize (2), searchforenvironmentsorroles (2), dependschefvault (2), cookbookusessearch (2), cookbookusesroles (2), cookbookusespolicygroups (2), cookbookusesenvironments (2), cookbookusesdatabags (2), chefvaultused (2), berksfile (2), windowsversionhelpers (2), windowstaskchangeaction (2), windowspackageinstallertypestring (2), windowsfeatureservermanagercmd (2), verifypropertyusesfileexpansion (2), useyamldump (2), usesruncommandhelper (2), usesdeprecatedmixins (2), useschefresthelpers (2), userdeprecatedsupportsproperty (2), useinlineresourcesdefined (2), useautomaticresourcename (2), searchusespositionalparameters (2), rubyblockcreateaction (2), ruby27keywordargumentwarnings (2), resourcewithoutunifiedtrue (2), resourceusesupdatedmethod (2), resourceusesproviderbasemethod (2), resourceusesonlyresourcename (2), resourceusesdslnamemethod (2), resourceoverridesprovidesmethod (2), resourceinheritsfromcompatresource (2), requirerecipe (2), powershellcookbookhelpers (2), policyfilecommunitysource (2), poisearchiveusage (2), partialsearchhelperusage (2), partialsearchclassusage (2), nodesetwithoutlevel (2), nodesetunless (2), nodeset (2), nodemethodsinsteadofattributes (2), nodedeepfetch (2), namepropertywithdefaultvalue (2), macosuserdefaultsglobalproperty (2), logresourcenotifications (2), localedeprecatedlcallproperty (2), librarianchefspec (2), legacyyumcookbookrecipes (2), legacynotifysyntax (2), launchddeprecatedhashproperty (2), includingyumdnfcompatrecipe (2), includingxmlrubyrecipe (2), hwrpwithoutunifiedtrue (2), hwrpwithoutprovides (2), foodcritictesting (2), foodcriticfile (2), executerelativecreateswithoutcwd (2), executepathproperty (2), erlcallresource (2), epicfail (2), eolauditmodeusage (2), easyinstallresource (2), deprecatedyumrepositoryproperties (2), deprecatedyumrepositoryactions (2), deprecatedwindowsversioncheck (2), deprecatedsudoactions (2), deprecatedshelloutmethods (2), deprecatedplatformmethods (2), deprecatedchefspecplatform (2), dependsonomnibusupdatercookbook (2), dependsonchefreportingcookbook (2), dependsonchefnginxcookbook (2), delivery (2), cookbooksdependsonself (2), cookbookdependsonpoise (2), cookbookdependsonpartialsearch (2), cookbookdependsoncompatresource (2), chocolateypackageuninstallaction (2), chefwindowsplatformhelper (2), chefsugarhelpers (2), chefspeclegacyrunner (2), chefspeccoveragereport (2), chefshellout (2), chefrewind (2), chefhandlerusessupports (2), chefhandlerrecipe (2), cheffile (2), chefdkgenerators (2), tmppath (2), supportsmustbefloat (2), serviceresource (2), scopedfileexist (2), resourcewithnoneaction (2), resourcesetsnameproperty (2), resourcesetsinternalproperties (2), propertywithouttype (2), powershellscriptdeletefile (2), powershellfileexists (2), opensslpasswordhelpers (2), octalmodeasstring (2), notifiesactionnotsymbol (2), nodenormalunless (2), nodenormal (2), metadatamissingversion (2), metadatamissingname (2), metadatamalformeddepends (2), malformedplatformvalueforplatformhelper (2), macosuserdefaultsinvalidtype (2), lazyinresourceguard (2), lazyevalnodeattributedefaults (2), invalidversionmetadata (2), invalidplatformvalueforplatformhelper (2), invalidplatformvalueforplatformfamilyhelper (2), invalidplatformmetadata (2), invalidplatformincase (2), invalidplatformhelper (2), invalidplatformfamilyincase (2), invalidplatformfamilyhelper (2), invalidnotificationtiming (2), invalidnotificationresource (2), invaliddefaultaction (2), invalidcookbookname (2), incorrectlibraryinjection (2), emptyresourceguard (2), dnfpackageallowdowngrades (2), cookbookusesnodesave (2), conditionalrubyshellout (2), chefapplicationfatal (2), blockguardwithonlystring (2), correctness (2), v25 (2), tuning (2), failure (2), optional (2), airgap (2), capacity (2), planning (2), plan (2), base (2), 2025 (2), refresh (2), strategy (2), membership (2), rbac (2), keys (2), rotate (2), ssl (2), certs (2), separate (2), artifactory (2), artifact (2), store (2), warm (2), spare (2), env (2), windows_update_settings (2), windows_power_management (2), windows_password_policy (2), windows_ie_esc (2), windows_firewall (2), windows_disk_encryption (2), windows_desktop_winrm_settings (2), windows_desktop_screensaver (2), windows_defender_exclusion (2), windows_defender (2), windows_choco_installer (2), windows_automatic_logout (2), windows_app_management (2), windows_admin_control (2), rescue_account (2), macos_power_management (2), macos_password_policy (2), macos_firewall (2), macos_disk_encryption (2), macos_desktop_screensaver (2), macos_automatic_software_updates (2), macos_automatic_logout (2), macos_app_management (2), macos_admin_control (2), windows (2), macos (2), zero (2), redirect (2), sso (2), opsworks (2), skills (2), administration (2), guides (2), enroll (2), clis (2), san (2), best (2), practices (2), cli (2), incident (2), servicenow (2), marketplace (2), scan (2), reports (2), eas (2), event (2), feed (2), teams (2), policies (2), actions (2), projects (2), lifecycle (2), feeds (2), notifications (2), cleanup (2), centralize (2), large (2), report (2), ingestion (2), invalid (2), login (2), attempts (2), telemetry (2), timeout (2), disclosure (2), panel (2), banner (2), collection (2), topics (2), manager (2), bastion (2), machine (2), rds (2), vpc (2), faqs (2), performance (2), benchmarks (2), rotation (2), self (2), signed (2), custom (2), commands (2), generation (2), efs (2), object (2), filesystem (2), customer (2), airgapped (2), tutorial (2), shortcodes (2), front (2), matter (2), reuse (2), hugo (2), procedures (2), tables (2), headings (2), notices (2), markdown (2), lists (2), linking (2), formatting (2), tools (2), house (2), contribute (2), docs (2), guidelines (2), contributions (2), commercial (2), script (2), accept (2), training (2), blog (2), main (2), certain, registered, countries, appropriate, markings, contained, inclusion, imply, endorsement, affiliation, sponsorship, copyright, last, modified, february, cookie, privacy, trademark, site, map, thank, submit, fill, field, how, ask, stuck, edit, yes, helpful, includes, utility, named, stop, tail, externally, resolvable, either, ipv6, ip_version, true, print, deltas, templates, false, hide_sensitive, fqdns, always, lowercase, guidance, various, going, reliability, stability, uptime, databases, index, election, refrain, unless, advised, sample, due, way, built, modifying, lead, instability, latest, providing, date, bring, attention, filling, ticket, installer, necessary, located, manifest, containing, superuser, instance, launching, erlang, epmd, second, column, sys, 0640, mode, secret, generates, present, role, follows, vulnerable, passive, traffic, prevent, attacker, intercepting, recommends, iptables, equivalent, acl, restrict, hosts, encrypted, expected, trusted, environment, means, untrusted, eavesdrop, potentially, identical, guarantees, change, occurs, complete, connection, result, reach, member, reconfiguring, created, overwritten, continue, yournet, might, authorize, allows, controls, four, once, updated, perform, upgraded, associate, admins, white, character, 1023, letter, digit, letters, digits, hyphens, underscores, 255, short_name, full_organization_name, jane, doe, janed, com, abc123, first_name, last_name, email, file_name, directions, knife, mkdir, pivotal, webui_pub, webui_priv, prior, assuming, detailed, made, ip_fe1, 6640, 43s, offline, syncing, synced, 6788, 35s, waiting, 6742, 39s, health, healthy, 6661, 41s, distributed, return, something, like, repeat, steps, now, answer, prompts, regarding, alternative, manually, prompted, publish, ip_be1, don, sequence, parallel, fail, become, delete, destination, completed, joined, ip_be3, ip_be2, directly, expose, common, mounted, section, initialize, comes, completes, synchronization, protocol, ntp, drift, less, than, seconds, boxes, belong, desired, required, vary, who, build, before, creating, building, least, part, already, instructions, assume, minimum, 9400, 2380, 9300, 7331, 443, https, http, rest, stored, individually, sticky, sessions, operates, quickly, behavior, operations, writing, unpredictable, 8gb, free, 4gb, bit, general, both, guideline, tend, cpu, memory, managing, rule, allocate, per, below, want, later, count, grows, tested, installations, numbers, starting, instances, internal, flexible, clustering, while, maintaining, compatibility, apache, solr, doing, deployments, meant, geographically, dispersed, regions, datacenters, however, providers, deploy, zones, within, region, working, together, persistence, scaled, horizontally, increasing, operate, automated, balancing, failover, stateful, typically, splits, segments, introduces, underlying, concepts, behind, describes, five, maintained, development, representative, migrating, deprecated, menu, skip,
Text of the page (random words):
premises premium storage in microsoft azure ebs optimized gp2 in aws warning the chef infra server must not use a network file system of any type virtual or physical for backend storage the chef infra server database operates quickly the behavior of operations such as the writing of log files will be unpredictable when run over a network file system network services a load balancer between the rest of the network and the frontend group not provided because management console session data is stored on each node in the frontend group individually the load balancer should be configured with sticky sessions network port requirements inbound from load balancer to frontend group tcp 80 http tcp 443 https inbound from frontend group to backend cluster tcp 2379 etcd tcp 5432 postgresql tcp 7331 leaderl tcp 9200 9300 elasticsearch peer communication backend cluster 2379 etcd 2380 etcd 5432 postgresql 9200 9400 elasticsearch installation these instructions assume you are using the minimum versions chef server 12 5 0 chef backend 0 8 0 download chef infra server and chef backend from chef downloads if you do not have them already before creating the backend ha cluster and building at least one chef infra server to be part of the frontend group verify the user who will install and build the backend ha cluster and frontend group has root access to all nodes the number of backend and frontend nodes that are desired it is required to have three backend nodes but the number of frontend nodes may vary from a single node to a load balanced tiered configuration ssh access to all boxes that will belong to the backend ha cluster from the node that will be the initial bootstrap a time synchronization policy is in place such as network time protocol ntp drift of less than 1 5 seconds must exist across all nodes in the backend ha cluster step 1 create cluster the first node must be bootstrapped to initialize the cluster the node used to bootstrap the cluster will be the cluster leader when the cluster comes online after bootstrap completes this node is no different from any other back end node install the chef backend package on the first backend node as root download chef backend chef backend in red hat centos yum install path_to_rpm in debian ubuntu dpkg i path_to_deb update etc chef backend chef backend rb with the following content publish_address external_ip_address_of_this_box external ip address of this backend box if any of the backends or frontends are in different networks from each other then add a postgresql md5_auth_cidr_addresses line to etc chef backend chef backend rb with the following content where net 1_in_cidr net n_in_cidr is the list of all of the networks that your backends and frontends are in see the configuring frontend and backend members on different networks section for more information publish_address external_ip_address_of_this_box external ip address of this backend box postgresql md5_auth_cidr_addresses samehost samenet net 1_in_cidr net n_in_cidr run chef backend ctl create cluster step 2 shared credentials the credentials file etc chef backend chef backend secrets json generated by bootstrapping must be shared with the other nodes you may copy them directly or expose them via a common mounted location for example to copy using ssh scp etc chef backend chef backend secrets json user ip_be2 home user scp etc chef backend chef backend secrets json user ip_be3 home user delete this file from the destination after step 4 has been completed for each backend being joined to the cluster step 3 install and configure remaining backend nodes for each additional node do the following in sequence if you attempt to join nodes in parallel the cluster may fail to become available install the chef backend package on the node download chef backend chef backend in red hat centos yum install path_to_rpm in debian ubuntu dpkg i path_to_deb if you added a postgresql md5_auth_cidr_addresses line to the leader s etc chef backend chef backend rb in step 1 create cluster then update this node s etc chef backend chef backend rb with the following content where postgresql md5_auth_cidr_addresses is set to the same value used in the leader s chef backend rb if all of the backend and frontend clusters are in the same network then you don t need to modify this node s etc chef backend chef backend rb at all publish_address external_ip_address_of_this_box external ip address of this backend box postgresql md5_auth_cidr_addresses samehost samenet net 1_in_cidr net n_in_cidr as root or with sudo chef backend ctl join cluster ip_be1 s home user chef backend secrets json answer the prompts regarding which public ip to use as an alternative you may specify them on the chef backend join cluster command line see chef backend ctl join cluster help for more information if you manually added the publish_address line to etc chef backend chef backend rb then you will not be prompted for the public ip and you should not use the publish address option to specify the the public ip on the chef backend join cluster command line if you copied the shared chef backend secrets json file to a user home directory on this host remove it now repeat these steps for each follower node after which the cluster is online and available from any node in the backend ha cluster run the following command chef backend ctl status should return something like service local status time in state distributed node status elasticsearch running pid 6661 1d 5h 59m 41s state green nodes online 3 3 etcd running pid 6742 1d 5h 59m 39s health green healthy nodes 3 3 leaderl running pid 6788 1d 5h 59m 35s leader 1 waiting 0 follower 2 total 3 postgresql running pid 6640 1d 5h 59m 43s leader 1 offline 0 syncing 0 synced 2 step 4 generate chef infra server configuration log into the node from step 1 and generate a chef server frontend node configuration chef backend ctl gen server config fe1 fqdn f chef server rb fe1 scp chef server rb fe1 user ip_fe1 home user note etc chef backend chef backend secrets json is not made available to chef infra server frontend nodes step 5 install and configure the first frontend on the first frontend node assuming that the generated configuration was copied as detailed in step 4 install the current chef server core package copy the file to etc opscode with cp home user chef server rb fe1 etc opscode chef server rb as root run chef server ctl reconfigure step 6 adding more frontend nodes for each additional frontend node you wish to add to your cluster install the current chef server core package generate a new etc opscode chef server rb from any of the backend nodes via chef backend ctl gen server config fe_name fqdn chef server rb fe_name copy it to etc opscode on the new frontend node from the first frontend node configured in step 5 copy the following files from the first frontend to etc opscode on the new frontend node etc opscode private chef secrets json note for chef server versions prior to 12 14 you will also need to copy the key files etc opscode webui_priv pem etc opscode webui_pub pem etc opscode pivotal pem on the new frontend node run mkdir p var opt opscode upgrades from the first frontend node copy var opt opscode upgrades migration level to the same location on the new node on the new frontend run touch var opt opscode bootstrapped on the new frontend as root run chef server ctl reconfigure step 7 configure the server note to restore a backup to this system follow the chef server ctl or the knife ec restore directions run the following command to create an administrator sudo chef server ctl user create user_name first_name last_name email password filename file_name an rsa private key is generated automatically this is the user s private key and should be saved to a safe location the filename option will save the rsa private key to the specified absolute path for example sudo chef server ctl user create janedoe jane doe janed example com abc123 filename path to janedoe pem run the following command to create an organization sudo chef server ctl org create short_name full_organization_name association_user user_name filename organization validator pem for example sudo chef server ctl org create 4thcafe fourth cafe inc association_user janedoe filename path to 4thcafe validator pem the name must begin with a lower case letter or digit may only contain lower case letters digits hyphens and underscores and must be between 1 and 255 characters for example 4thcafe the full name must begin with a non white space character and must be between 1 and 1023 characters for example fourth cafe inc the association_user option will associate the user_name with the admins security group on the chef infra server an rsa private key is generated automatically this is the chef validator key and should be saved to a safe location the filename option will save the rsa private key to the specified absolute path upgrading chef infra server on the frontend machines on one frontend server follow the standalone upgrade process copy var opt opscode upgrades migration level from the first upgraded frontend to var opt opscode upgrades migration level on each of the remaining frontends once the updated file has been copied to each of the remaining frontends perform the standalone upgrade process on each of the frontend servers configuring frontend and backend members on different networks by default postgresql only allows systems on its local network to connect to the database server that runs it and the pg_hba conf used by postgresql controls network access to the server the default pg_hba conf has the following four entries host all all samehost md5 hostssl replication replicator samehost md5 host all all samenet md5 hostssl replication replicator samenet md5 to allow other systems to connect such as members of a frontend group that might exist on a different network you will need to authorize that usage by adding the following line to the etc chef backend chef backend rb file on all of the backend members postgresql md5_auth_cidr_addresses samehost samenet yournet in cidr after setting the md5_auth_cidr_addresses value and reconfiguring the server two entries will be created in pg_hba conf for each value in the md5_auth_cidr_addresses array existing values in pg_hba conf will be overwritten by the values in the array so we must also specify samehost and samenet which will continue to allow systems on a local network to connect to postgresql for example if a frontend host at 192 168 1 3 can reach a backend member over the network but the backend s local network is 192 168 2 x you would add the following line to etc chef backend chef backend rb postgresql md5_auth_cidr_addresses samehost samenet 192 168 1 3 24 which would result in the following two entries being added to the pg_hba conf file host all all samehost md5 hostssl replication replicator samehost md5 host all all samenet md5 hostssl replication replicator samenet md5 host all all 192 168 1 3 24 md5 hostssl replication replicator 192 168 1 3 24 md5 running chef backend ctl reconfigure on all the backends will allow that frontend to complete its connection important the postgresql md5_auth_cidr_addresses subnet settings must be identical for all members of the backend cluster in the case where the subnet settings of the frontend cluster are different from the subnet settings of the backend cluster the values set on the members of the backend cluster should contain the subnet of the frontend cluster this guarantees that all members of a cluster can still communicate with each other after a cluster change of state occurs for example if the frontend subnet setting is 192 168 1 0 24 and the backend subnet setting is 192 168 2 0 24 then the postgresql md5_auth_cidr_addresses subnet settings must be postgresql md5_auth_cidr_addresses samehost samenet 192 168 1 0 24 192 168 2 0 24 cluster security considerations a backend cluster is expected to run in a trusted environment this means that untrusted users that communicate with and or eavesdrop on services provided by the backend cluster can potentially view sensitive data communication between nodes postgresql communication between nodes in the backend cluster is encrypted and uses password authentication all other communication in the backend cluster is unauthenticated and happens in the clear without encryption communication between frontend group backend cluster postgresql communication from nodes in the frontend group to the leader of the backend cluster uses password authentication but communication happens in the clear without encryption elasticsearch communication is unauthenticated and happens in the clear without encryption securing communication because most of the peer communication between nodes in the backend cluster happens in the clear the backend cluster is vulnerable to passive monitoring of network traffic between nodes to help prevent an active attacker from intercepting or changing cluster data chef recommends using iptables or an equivalent network acl tool to restrict access to postgresql elasticsearch and etcd to only hosts that need access by service role access requirements are as follows service access requirements postgresql all backend cluster members and all chef infra server frontend group nodes elasticsearch all backend cluster members and all chef infra server frontend group nodes etcd all backend cluster members and all chef infra server frontend group nodes services and secrets communication with postgresql requires password authentication the backend cluster generates postgresql users and passwords during the initial cluster create these passwords are present in the following files on disk secret owner group mode etc chef backend secrets json root chef_pgsql 0640 var opt chef backend leaderl data sys config chef_pgsql chef_pgsql 0600 var opt chef backend postgresql 9 5 recovery conf chef_pgsql chef_pgsql 0600 the following services run on each node in the backend cluster the user account under which the service runs as listed the second column service process owner postgresql chef_pgsql elasticsearch chef backend etcd chef backend leaderl chef_pgsql epmd chef_pgsql or first user launching an erlang process chef infra server frontend the chef backend ctl gen server config command which can be run as root from any node in the backend cluster will automatically generate a configuration file containing the superuser database access credentials for the backend cluster postgresql instance software versions the backend ha cluster uses the chef installer to package all of the software necessary to run the services included in the backend cluster for a full list of the software packages included and their versions see the file located at opt chef backend version manifest json do not attempt to upgrade individual components of the chef package due to the way chef packages are built modifying any of the individual components in the package...
|