Re: policy_server.dat IP to DNS
"'Nick Anderson' via help-cfengine" <[email protected]> Fri, 24 Oct 2025 14:45:56 -0500
| Newsgroups | gmane.comp.sysutils.cfengine.general |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: multipart/alternative; boundary="==-=-=" --==-=-= Content-Type: text/plain; charset="UTF-8" IN_PROGRESS Respond to Markus Rexhepi-Lindberg <[email protected]>: Re: [help-cfengine] policy_server.dat IP to DNS :CFEngine:email: ======================================================================================================================= > When you --bootstrap , the content in $(sys.input_dir) is wiped and completely re-seeded. If your bootstrap fails you will not have a full policy in inputs, where as if you re-write policy_server.dat your existing policy will remain in place and the next time the agent starts it will resolve the new value for policy server. Does this mean next time cf-agent executes or when the cf daemons (re)starts? Yes the next time cf-agent is executed from it's perspective it will have the new policy server address. The daemons each have their own perspective. When they re-evaluate the policy they should also re-load the policy_server.dat. The daemon might realize the need to re-evaluate it's policy on it's own, or it might not and it might need to be re-started, it depends on specifically what changed (actual policy .cf files or external data), I don't think that the daemons key need for policy re-load in relation to a policy_server.dat change. The value derived from policy_server.dat is used in default MPF access rules so for example cf-serverd having a stale value would impact the new policy servers ability to access the host (if you have a case where the hub is collecting things from the client, e.g. enterprise or some policy to copy files from the client). -- You received this message because you are subscribed to the Google Groups "help-cfengine" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%40northern.tech. --==-=-= Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <blockquote style=3D"border-left: 2px solid gray; padding-left: 4px;"> <p> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"> <div>When you –bootstrap , the content in $(sys.input_dir) is wiped = and completely re-seeded. If your bootstrap fails you will not have a full = policy in inputs, where as if you re-write policy_server.dat your existing = policy will remain in place and the next time the agent starts it will reso= lve the new value for policy server. </div></blockquote> </p> <p> Does this mean next time cf-agent executes or when the cf daemons (re)start= s? </p> </blockquote> <p> Yes the next time cf-agent is executed from it's perspective it will have t= he new policy server address. </p> <p> The daemons each have their own perspective. When they re-evaluate the poli= cy they should also re-load the policy_server.dat. The daemon might realize= the need to re-evaluate it's policy on it's own, or it might not and it mi= ght need to be re-started, it depends on specifically what changed (actual = policy .cf files or external data), I don't think that the daemons key need= for policy re-load in relation to a policy_server.dat change. </p> <p> The value derived from policy_server.dat is used in default MPF access rule= s so for example cf-serverd having a stale value would impact the new polic= y servers ability to access the host (if you have a case where the hub is c= ollecting things from the client, e.g. enterprise or some policy to copy fi= les from the client). </p> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;help-cfengine" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">help-= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/d/msgid/= help-cfengine/87bjlwcccp.fsf%40northern.tech?utm_medium=3Demail&utm_source= =3Dfooter">https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%4= 0northern.tech</a>.<br /> --==-=-=-- --=-=-= Content-Type: text/plain; charset="UTF-8" -- Nick Anderson | Doer of Things | (+1) 785-550-1767 | https://northern.tech -- You received this message because you are subscribed to the Google Groups "help-cfengine" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/help-cfengine/87bjlwcccp.fsf%40northern.tech. --=-=-=--