You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Issue #32 added initial support for setting up multiple Check_MK monitoring sites in a distributed setup. It will create a dedicated 'sitesync' account for configuration synchronization. However, when running a playbook with a distributed setup, the following error is thrown:
Reason: The default password configuration for the site login from the master site is defined in checkmk_server__distributed_sites_defaults which points to the own 'sitesync' account credential. However, when creating a slave site, a new set of default credentials will be generated as defined in checkmk_server__multisite_debops_users. These secret paths don't match.
Work-around: It is possible to set the checkmk_server__distributed_sites.<slave_site>.password definition to the secret path of the master server. But as the slave site (inventory configuration) doesn't know anything about the master, it has to be explicitly configured by the user which is cumbersome.
But attention: After the initial configuration sync to the slave site, the originally defined site accounts will be overwritten with the accounts of the master site (including passwords), which completely invalidates individual inventory secrets for the slave site used by Ansible.
A possible solution(?) would be to symlink the slave site secret directory to the master site. However this must be done properly to avoid the secret to be accessed before the symlink is generated...
The text was updated successfully, but these errors were encountered:
Issue #32 added initial support for setting up multiple Check_MK monitoring sites in a distributed setup. It will create a dedicated 'sitesync' account for configuration synchronization. However, when running a playbook with a distributed setup, the following error is thrown:
Reason: The default password configuration for the site login from the master site is defined in
checkmk_server__distributed_sites_defaults
which points to the own 'sitesync' account credential. However, when creating a slave site, a new set of default credentials will be generated as defined incheckmk_server__multisite_debops_users
. These secret paths don't match.Work-around: It is possible to set the
checkmk_server__distributed_sites.<slave_site>.password
definition to the secret path of the master server. But as the slave site (inventory configuration) doesn't know anything about the master, it has to be explicitly configured by the user which is cumbersome.But attention: After the initial configuration sync to the slave site, the originally defined site accounts will be overwritten with the accounts of the master site (including passwords), which completely invalidates individual inventory secrets for the slave site used by Ansible.
A possible solution(?) would be to symlink the slave site secret directory to the master site. However this must be done properly to avoid the secret to be accessed before the symlink is generated...
The text was updated successfully, but these errors were encountered: