Running Puppet(Master) on port 443

473 views
Skip to first unread message

Dan White

unread,
Feb 8, 2012, 4:37:17 PM2/8/12
to Pupper Users Mailing List
On Feb 1, 2012, at 8:06 PM, Nan Liu wrote:
> Puppet uses REST, so you can run puppet master on 443 to work around firewalls.

I would like to get a bit more information on this.

Is it as simple as setting all the ports in puppet.conf to 443 on master and agent ?

“Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us.”
Bill Waterson (Calvin & Hobbes)

Michael Stahnke

unread,
Feb 8, 2012, 4:50:16 PM2/8/12
to puppet...@googlegroups.com
On Wed, Feb 8, 2012 at 1:37 PM, Dan White <yg...@comcast.net> wrote:
> On Feb 1, 2012, at 8:06 PM, Nan Liu wrote:
>> Puppet uses REST, so you can run puppet master on 443 to work around firewalls.
>
> I would like to get a bit more information on this.
>
> Is it as simple as setting all the ports in puppet.conf to 443 on master and agent ?

Yes, and ensuring you don't have anything else using 443 on the server.

Once you've changed it try

Mike


>
> “Sometimes I think the surest sign that intelligent life exists elsewhere in the universe is that none of it has tried to contact us.”
> Bill Waterson (Calvin & Hobbes)
>

> --
> You received this message because you are subscribed to the Google Groups "Puppet Users" group.
> To post to this group, send email to puppet...@googlegroups.com.
> To unsubscribe from this group, send email to puppet-users...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/puppet-users?hl=en.
>

Dan White

unread,
Feb 8, 2012, 9:00:54 PM2/8/12
to puppet...@googlegroups.com

On Feb 8, 2012, at 4:50 PM, Michael Stahnke wrote:

> On Wed, Feb 8, 2012 at 1:37 PM, Dan White <yg...@comcast.net> wrote:
>> On Feb 1, 2012, at 8:06 PM, Nan Liu wrote:
>>> Puppet uses REST, so you can run puppet master on 443 to work around firewalls.
>>
>> I would like to get a bit more information on this.
>>
>> Is it as simple as setting all the ports in puppet.conf to 443 on master and agent ?
>
> Yes, and ensuring you don't have anything else using 443 on the server.
>
> Once you've changed it try

Ah ha, and there is the twist.
I cannot guarantee something else would want to use that port.

Seems it would be easier to negotiate the additional holes for 8139/8140 in the firewall

Reply all
Reply to author
Forward
0 new messages