Fix krb5 with failover
Seems like IPA 4.5.0 broke active/active failover of krb5 KDC. While we wait on getting that fixed, let's set us up for active/passive failover on the HTTPD end. Since we can't do active/passive for UDP (there's no checks there), let's just remove ipa02 for those. Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
This commit is contained in:
parent
369a68a5a2
commit
4005fd5929
1 changed files with 2 additions and 2 deletions
|
@ -340,7 +340,7 @@ listen ipa 0.0.0.0:10053
|
||||||
balance hdr(appserver)
|
balance hdr(appserver)
|
||||||
server ipa01 ipa01:443 check inter 10s rise 1 fall 2 ssl verify required ca-file /etc/haproxy/ipa.pem
|
server ipa01 ipa01:443 check inter 10s rise 1 fall 2 ssl verify required ca-file /etc/haproxy/ipa.pem
|
||||||
{% if env != "staging" %}
|
{% if env != "staging" %}
|
||||||
server ipa02 ipa02:443 check inter 10s rise 1 fall 2 ssl verify required ca-file /etc/haproxy/ipa.pem
|
server ipa02 ipa02:443 check inter 10s rise 1 fall 2 ssl verify required ca-file /etc/haproxy/ipa.pem backup
|
||||||
{% endif %}
|
{% endif %}
|
||||||
option httpchk GET /ipa/ui/
|
option httpchk GET /ipa/ui/
|
||||||
|
|
||||||
|
@ -354,7 +354,7 @@ listen krb5 0.0.0.0:1088
|
||||||
timeout connect 86400000
|
timeout connect 86400000
|
||||||
server ipa01 ipa01:88 weight 1 maxconn 16384
|
server ipa01 ipa01:88 weight 1 maxconn 16384
|
||||||
{% if env == "production" %}
|
{% if env == "production" %}
|
||||||
server ipa02 ipa02:88 weight 1 maxconn 16384
|
# server ipa02 ipa02:88 weight 1 maxconn 16384
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
||||||
listen docker-candidate-registry 0.0.0.0:10054
|
listen docker-candidate-registry 0.0.0.0:10054
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue