Puppet 2.7 Released
groups.google.com
groups.google.com
I've been looking at Puppet and Chef, but we're not just Rails anymore and I can't imagine that the Ruby world's tools are the only popular ones. I just don't know where to look for how to make an informed choice, how to get started, etc. It feels like there is a large gap in available knowledge between running a couple of processes on a single server and anything I'd trust to some paying customers.
We use Puppet at Disqus (a Python shop). Puppet and Chef are used by pretty much any modern web deployment that didn't already have a system in something more dated (cfengine? custom made?). At least that's the feeling I get.
I can't speak much to Chef but Puppet has great docs. You might just get an intro book for one or the other and dive in.
Note that the easiest way to start is to not use any of puppet's built-in client-server stuff (puppetd command). Instead run everything like this:
$ git clone $REMOTE_REPO_WITH_MANIFESTS puppet
$ ls
manifests modules
$ sudo puppet --modulepath=modules/ --debug manifests/site.pp
You could use something like fabric if you only have 1-2 servers.cfengine has been around longer, but seems to have negative adoption since puppet became well-known. I know a few people who swear by it, though.
FWIW, at my current startup I use Chef to manage a mid-sized collection of servers (app, load balancers, DBs/replicas, task processors) where the app is written mostly in Python, and it took a ton of pain out of scaling up to deal with a very large paying customer two nights ago.
Puppet has better documentation, but learning either is a bit of a trial and error process I think. You might find Blueprint (https://github.com/devstructure/blueprint) useful to bootstrap (the authors are around in the HN community, I think.)
Blueprint (https://github.com/devstructure/blueprint)
Blueprint I/O (https://github.com/devstructure.com/blueprint-io)
The biggest pain is that the docs were iffy, at least for me. I wasn't the one setting up the servers at work, but when setting up a Chef cookbook for personal use, it was a pain to both learn the DSL and deal with the silliness caused by bugs that hadn't quite made it to release yet. At the end of the day though, its more just experimenting with the tools available until you're comfortable with one.
You can also look into Fabric, which is a Python server automation tool.
[1]http://ericholscher.com/blog/2010/nov/8/building-django-app-...
I've used both Puppet and Chef extensively, and they both do the same thing, they just go about it differently. (shameless plug of a blog post I wrote that compared the two: http://redbluemagenta.com/2011/05/21/puppet-vs-chef)
Also, it's almost always about how you approach configuration management - thankfully, with Puppet and Chef, you don't have to manage everything on a system in your CM right away. If you have to manage SSH authorized_key entries and it's getting annoying to do it by hand, then write a Puppet module / Chef cookbook to manage it for you. Then go on to manage /etc/hosts entries, then to deploying packages... you'll hit a point where you can reasonably rebuild a server from scratch without thinking about it.
There's other CM systems out there too: bcfg2, cfengine, etc.
http://www.usenix.org/publications/login/2010-10/openpdfs/Co...
To help you get started with Cfengine (my specialty):
http://www.cfengine.com/pages/tech http://www.verticalsysadmin.com/cfengine/cfengine_examples.t...
http://www.usenix.org/publications/login/2011-04/openpdfs/Lu...
Puppet is an enterprise systems management platform that standardizes the way IT staff deploy and manage infrastructure in the enterprise and the cloud.
By automating the provisioning, patching, and configuration of operating system and application components across infrastructure, Puppet enables IT staff to master their infrastructure even as complexity grows.
I am not deploying Ruby applications so I really don't like the idea of installing a bunch of software on my production servers. Not to mention that chef also installed a compiler on my server and that is a big no-no in my book.
Am I the only one that has an aversion of using these tools?
Puppet is also more lightweight than Chef in terms of the amount of dependencies it requires, given an already existing installation of Ruby (in fact, I think there's only one dependency: facter.) The only problem is that it comes with a lot less available language features out of the box than Chef, mainly because Puppet doesn't have a way to store and serve configurations of other machines out of the box without something backing the data store, like MySQL or CouchDB.
Is there a good replacement for Tripwire out there? It's a great toolset for change management and security, but is too expensive for my current endeavours. I played with an open source tool a couple of years ago that kind of sucked.