Secret Changers - Active Cluster Node

Active cluster node option determines the Fudo Enterprise instance responsible for changing secrets on monitored systems.

Note

Secret changers require at least two active nodes to operate. In a two-node setup, the failure of one node causes secret changers to stop working; therefore, a three-node setup is recommended.

  1. Select Settings > System.

  2. Select the General tab.

  3. In the Secret Changers section, select the node delegated to secret changing.

../../_images/5-6-pc-active-node.png
  1. Click Save.


Note

In case the node responsible for changing secrets fails, the task will not be automatically picked up by another Fudo Enterprise instance. In order to restore automatic secret changing, the system administrator will have to change the active secret changing node or bring back the failed node.

Cluster Secret Changers

Fudo Enterprise allows changing a secret on a different node than the one that set as an Active cluster node for Secret Changers. In order to have this configured, the following condition should be met:


Setting up a Secret Changer / Secret Verifier for an account, a value for transport_bind_ip variable should indicate the same cluster node for all secret changers as well as secret verifiers.

../../_images/6-0-accounts-pc-config.png

If the transport_bind_ip variable values indicate different cluster nodes, the configured secret changer/verifier will be running on a node that set as an Active cluster node for Secret Changers.


Related topics: