There are currently three local reverts on the cloud-vps puppetmasters. These were necessary to keep new VMs working properly. These need to be reverted upstream or the actual certs-on-new-VMs issue resolved.
commit 0f72a235e3704b9c08ab1294fa560f722aeb48bb Author: root <root@cloud-puppetmaster-01.cloudinfra.eqiad.wmflabs> Date: Tue Sep 10 02:40:03 2019 +0000 Revert "Puppet CAs: Make it easy to swap CAs by hiera change" This reverts commit 72e50df4ee34f506a98d250b97c88999712708ed. commit 55d265b630f8758e78b3efb0f815cafbe3d8b779 Author: root <root@cloud-puppetmaster-01.cloudinfra.eqiad.wmflabs> Date: Tue Sep 10 02:39:43 2019 +0000 Revert "Puppet certs: Move old client certs away when Puppet CA changes" This reverts commit 9694f8087f59f4bee73d2982a8ade9ac6adf6d89. commit 2f1fa863da51c4288cef25d611be824d2018857a Author: root <root@cloud-puppetmaster-01.cloudinfra.eqiad.wmflabs> Date: Tue Sep 10 02:38:49 2019 +0000 Revert "Make puppetmaster CA content key be a hash keyed by puppetmaster" This reverts commit 640666bec0afacd96313aefa52b141d9c72fac0b.