Re: policy_server.dat IP to DNS

"'Nick Anderson' via help-cfengine" <[email protected]> Fri, 24 Oct 2025 14:45:56 -0500
Newsgroups gmane.comp.sysutils.cfengine.general
Message-ID <[email protected]>
--=-=-=
Content-Type: multipart/alternative; boundary="==-=-="

--==-=-=
Content-Type: text/plain; charset="UTF-8"

IN_PROGRESS Respond to Markus Rexhepi-Lindberg <[email protected]>: Re: [help-cfengine] policy_server.dat IP to DNS :CFEngine:email:
=======================================================================================================================

        > When you --bootstrap , the content in $(sys.input_dir)
          is wiped and completely re-seeded. If your bootstrap
          fails you will not have a full policy in inputs, where
          as if you re-write policy_server.dat your existing
          policy will remain in place and the next time the agent
          starts it will resolve the new value for policy server.

        Does this mean next time cf-agent executes or when the cf
        daemons (re)starts?

  Yes the next time cf-agent is executed from it's perspective it will
  have the new policy server address.

  The daemons each have their own perspective. When they re-evaluate the
  policy they should also re-load the policy_server.dat. The daemon
  might realize the need to re-evaluate it's policy on it's own, or it
  might not and it might need to be re-started, it depends on
  specifically what changed (actual policy .cf files or external data),
  I don't think that the daemons key need for policy re-load in relation
  to a policy_server.dat change.

  The value derived from policy_server.dat is used in default MPF access
  rules so for example cf-serverd having a stale value would impact the
  new policy servers ability to access the host (if you have a case
  where the hub is collecting things from the client, e.g. enterprise or
  some policy to copy files from the client).

-- 
You received this message because you are subscribed to the Google Groups "help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%40northern.tech.

--==-=-=
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<blockquote style=3D"border-left: 2px solid gray; padding-left: 4px;">
<p>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">

<div>When you &#x2013;bootstrap , the content in $(sys.input_dir) is wiped =
and completely re-seeded. If your bootstrap fails you will not have a full =
policy in inputs, where as if you re-write policy_server.dat your existing =
policy will remain in place and the next time the agent starts it will reso=
lve the new value for policy server.

</div></blockquote>
</p>

<p>
Does this mean next time cf-agent executes or when the cf daemons (re)start=
s?
</p>
</blockquote>

<p>
Yes the next time cf-agent is executed from it's perspective it will have t=
he new policy server address.
</p>

<p>
The daemons each have their own perspective. When they re-evaluate the poli=
cy they should also re-load the policy_server.dat. The daemon might realize=
 the need to re-evaluate it's policy on it's own, or it might not and it mi=
ght need to be re-started, it depends on specifically what changed (actual =
policy .cf files or external data), I don't think that the daemons key need=
 for policy re-load in relation to a policy_server.dat change.
</p>

<p>
The value derived from policy_server.dat is used in default MPF access rule=
s so for example cf-serverd having a stale value would impact the new polic=
y servers ability to access the host (if you have a case where the hub is c=
ollecting things from the client, e.g. enterprise or some policy to copy fi=
les from the client).
</p>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;help-cfengine&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">help-=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/=
help-cfengine/87bjlwcccp.fsf%40northern.tech?utm_medium=3Demail&utm_source=
=3Dfooter">https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%4=
0northern.tech</a>.<br />

--==-=-=--

--=-=-=
Content-Type: text/plain; charset="UTF-8"




-- 
Nick Anderson | Doer of Things | (+1) 785-550-1767 | https://northern.tech

-- 
You received this message because you are subscribed to the Google Groups "help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%40northern.tech.

--=-=-=--