#7892 Implement hidden / unadvertised IPA replicas
Closed: fixed 5 years ago by cheimes. Opened 5 years ago by cheimes.

Implement the ability to have a hidden replica.

A hidden replica is an IPA master server that is not advertised to clients or other masters. Hidden replicas have all services running and available, but none of the services has any DNS SRV records or enabled LDAP server roles. This makes hidden replicas invisible for service discovery.


master:

  • 025facb Add hidden replica feature
  • 0770d8a ipatests: Exercise hidden replica feature
  • 99133eb Simplify and improve tests
  • 94b8635 Implement server-state --state=enabled/hidden
  • d810e1f Consider hidden servers as role provider
  • 56d97f9 Improve config-show to show hidden servers
  • f839d3c More test fixes
  • e7e0f19 Don't allow to hide last server for a role
  • 8b1bb21 Synchronize hidden state from IPA master role
  • e04dc9a Test replica installation from hidden replica
  • d727321 Add design draft
  • 713c9b0 Don't fail if config-show does not return servers

One remaining issue is that restoring a backup from a hidden replica results in an enabled (e.g. not hidden) server. Issue logged at https://pagure.io/freeipa/issue/7894

ipa-4-6:

  • cb85342 Add hidden replica feature
  • 016c47f ipatests: Exercise hidden replica feature
  • 7691162 Simplify and improve tests
  • da9f62d Implement server-state --state=enabled/hidden
  • d12cca4 Consider hidden servers as role provider
  • ed00466 Improve config-show to show hidden servers
  • 131c1ab More test fixes
  • bcf70c5 Don't allow to hide last server for a role
  • d8d6799 Synchronize hidden state from IPA master role
  • e40d92f Test replica installation from hidden replica
  • d1eb4c7 Add design draft
  • a0f00e6 Don't fail if config-show does not return servers

ipa-4-7:

  • ddf8e16 Add hidden replica feature
  • f96f4a1 ipatests: Exercise hidden replica feature
  • 585bc52 Simplify and improve tests
  • f3daa45 Implement server-state --state=enabled/hidden
  • 0bf26c5 Consider hidden servers as role provider
  • de1a075 Improve config-show to show hidden servers
  • 3e2fb21 More test fixes
  • dc2a5ec Don't allow to hide last server for a role
  • 87f9119 Synchronize hidden state from IPA master role
  • 467ceaf Test replica installation from hidden replica
  • 66c961d Add design draft
  • c76620e Don't fail if config-show does not return servers

Metadata Update from @cheimes:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

5 years ago

Login to comment on this ticket.

Metadata