Cfengine or puppet?

Thread Tools Search this Thread
Special Forums UNIX and Linux Applications Cfengine or puppet?
# 1  
Old 11-03-2013
Cfengine or puppet?

I'm looking to deploy a configuration management system at my company and was wondering which config management was better: cfengine or Puppet? Pros/Cons? I'm looking to deploy the free version of each.

Any advice would be greatly appreciated. Thanks.
# 2  
Old 11-03-2013
I used cfengine for 2 years. After switching to puppet I relised that I'll not chage it ever for something else

Puppet has a realy great community and support. So you'll find mode help about puppet or patches if needed than cfengine. This is my opinion. I know there are people out there how think cfengine is better, and if cfengine works well for them thats fine for me. But cfengine in my opinion does't have a bright future as puppet.

So my advice is to go with puppet.

Last edited by theboogymaster; 11-03-2013 at 01:53 PM..
This User Gave Thanks to theboogymaster For This Post:
# 3  
Old 11-03-2013
I'll give Puppet a shot.

I'm currently trying out CFEngine, and I am having a really hard time wrapping my head around the syntax.

Thanks for your input! Anymore input from anyone else would be greatly appreciated as well. Thanks!
# 4  
Old 11-03-2013
Puppet tries to ensure quality.
CFengine is a hack.
If you are not a genius, go for puppet. If you are a genius, you rather build your own distribution infrastructure.
# 5  
Old 11-04-2013
CFEngine is based on 20 years of research, and everything but a hack. CFEngine runs on more servers throughout the world than any other system, and is especially trusted among financial and telecom organizations.

Some find It harder to learn CFEngine than Puppet, because there is more to learn. CFEngine offers more granularity while Puppet offers abstractions (makes decision on behalf of the user)

If security is important to your organization, be careful with Puppet. According to NIST National Vulnerability Database, they have more than 20 incidents so far this year.
These 2 Users Gave Thanks to RaspberryFan For This Post:
# 6  
Old 11-04-2013
Does anyone have experience with ansible ?
# 7  
Old 11-04-2013
I tend to agree with Raspberry Fan. It is anything but a hack. In full transparency, I work for CFEngine, but would also go on to say I evaluated Puppet and other such recent technologies as part of my previous job at VMware.

The question to ask imho is not whether you should use Puppet or CFEngine or Ansible, but what it is you are trying to achieve.

CFEngine is robust technology, that is built on fundamentals of promise theory. Look it up and also look up autonomous automation.
On the practical side, its the most secure software in this category having no NIST vulnerabilities to date. Also it is much more scalable than the 200-300 servers/entities some of these other softwares can manage.
Lastly, if you are looking for a 'fire and forget' approach and believe system administration is about managing routine and mundane tasks day in and day out cfengine could do that very well. But then you must also believe systems are immutable as well a fallacy on which these fire and forget softwares are built.
But if you are looking for a truly autonomous sytem one that is lightweight, super scalabale (talking thousands of machines served by a policy master), secure, and has the capability to provide autonomic control in your infarastructure only CFEngine does it.
And lets dispel this myth. The power you get from spending some time with the CFEngine rewards you many times over. But if you want to take the easy approach there are enough useful abstractions in CFE as well to get you started.

So, there you go. It all depends on what you want to do and why you want to do so, before you choose how.


---------- Post updated at 04:30 PM ---------- Previous update was at 04:20 PM ----------

you may also find some of these thoughts interesting as you make your decision would be great to know what you find independently as we value your opinions and reasons for choosing or not choosing to go with CFEngine

I cant post URL's here and dont want to spam either so here are some resources for you to do independent study:
1. look for marco's blog and reasoning for "why i gave up puppet and chose cfengine"
edit by Scott: added link to blog post

2. there are other neat use cases (both routine and extreme in terms of scale/leveraging ec2 spot rates etc) that have been presented by LinkedIn, percolate... etc. look on youtube or the cfengine website

3. and as pointed out some of the largest fin-serv orgs are users of cfengine. JPMC being one of them and having inducted CFEngine into the hall of fame. search for it and you can see why managing directors on at JPMC they feel CFEngine is solid technology bar none when it comes to automation software

I doubt a software that is a "hack" would get this kind of credibility!!
These 2 Users Gave Thanks to maheshkumar For This Post:
Login or Register to Ask a Question

Previous Thread | Next Thread

7 More Discussions You Might Find Interesting

1. UNIX for Beginners Questions & Answers

Puppet : How to start.

Hello Team, Do You have any data/books/links related to Puppet? How to start, how to setup first env and execute "puppet" actions? Thanks in advance! Patryk (3 Replies)
Discussion started by: nsmcny
3 Replies

2. UNIX and Linux Applications

Puppet, Instillation

Can not complete the installation of a puppet server on a Linux box. bash: passenger-install-apache2-module: command not found Please use CODE tags as required by forum rules whenever you display sample input, sample output, and code segments. (1 Reply)
Discussion started by: zbest1966
1 Replies

3. UNIX and Linux Applications

Puppet dashboard

Hello all, can you please let me know if the free version of puppet provides dashboard? Or how do you get info about failed installation or other staff for the puppet agents? Sorry for not googling first :) (3 Replies)
Discussion started by: Vit0_Corleone
3 Replies

4. UNIX for Advanced & Expert Users

Need help installing Puppet and Ruby..

Hi, I am working on RHEL 5.6 server, this is in private DMZ. No access to internet. I have downloaded the files I need to install the Puppet & Ruby. My goal is to install Puppet. I have downloaded.... mcollective-2.2.3-1.el5.noarch- SERVER.rpm ... (2 Replies)
Discussion started by: samnyc
2 Replies

5. UNIX for Dummies Questions & Answers

Help installling puppet

Hi, I am trying to instal the puppet. I get this error. Please help.. yum install puppet-server Loaded plugins: fastestmirror, presto Loading mirror speeds from cached hostfile * base: * extras: * updates:... (2 Replies)
Discussion started by: samnyc
2 Replies

6. UNIX for Advanced & Expert Users

Cfengine vs OpenWRT

Hi! Im using Cfengine for Debian servers administration and know i have to manage to include some devices with openwrt firmware. Does someone know of a Cfengine client (cfagent) developed for OpenWRT? Thanks, Santiago (0 Replies)
Discussion started by: sbrandi
0 Replies

7. Red Hat

cfengine / puppet for rhel servers

Hello all, I am planning to deploy a configuration / auditing software package for about 100 new nodes that we are planning to install. I am hearing many good things in regards to cfengine and puppet. Can someone shed some light in regards to these solutions? Thanks, jaysunn (1 Reply)
Discussion started by: jaysunn
1 Replies
Login or Register to Ask a Question