3 ms·
Not to mention losing load balancing and failover.
by bot403 4mo ago
Not to mention losing load balancing and failover.
- dzr0001 4mo agoAnd making TLS more difficult, especially for HA systems. Guess you would just need one cert for 127.0.0.1 for all local services.
- louwrentius 4mo agoCerts support ip addresses? However, /etc/hosts would solve the issue probably, unless I’m missing something
- flumpcakes 4mo agoWhat has /etc/hosts got to do with valid TLS certificates? I think that’s a non-sequitur.
- louwrentius 4mo agoYou don't need to setup one cert for 127.0.0.1 as stated by the parent comment.
- throw0101a 4mo agoFailover can be done with something like keepalived. VRRP/CARP are a thing. For LB you'll need something in front of your service to bounce connections around, which is replacing one point of failure (DNS) for another (HAproxy, IPVS). Though I guess you can run the LB stack on your app service servers.