Orchestrator Pool Management

OrchestratorClosed Keyfactor orchestrators perform a variety of functions, including managing certificate stores and SSH key stores. pools are used to group one or more orchestrators for load balancing, scalability, and high-availability. Jobs created by Keyfactor Command—such as discovery, synchronization, or enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). tasks—are routed to a pool based on its configured capabilities.

Each orchestrator pool is configured with a set of capabilities that define the types of jobs it can accept. Orchestrators can be added to a pool regardless of the capabilities they individually declare. However, only jobs supported by both the pool’s configured capabilities and the combined capabilities of its member orchestrators will be executed.

Tip:  Some orchestrator roles are not managed by orchestrator pools, including SSLClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. scanning, orchestrator-managed CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. synchronization, and SSHClosed The SSH (secure shell) protocol provides for secure connections between computers. It provides several options for authentication, including public key, and protects the communications with strong encryption. key management. However, you can still create orchestrator pools for these orchestrators to support automatic registration and approval. This can be useful when you have many orchestrators or use short-lived orchestrators. Orchestrator pools created for this purpose would define no capabilities.

An orchestrator can belong to only one pool at a time. This ensures clear job routing and prevents contention between pools.

Note:  All orchestrators are associated with an orchestrator pool. Older orchestrators that do not support high availability use auto-generated, one-to-one pools. These pools are created automatically and cannot be managed directly. Universal Orchestrator versions that support high availability can be added to user-managed pools, which can contain multiple orchestrators.

From this page, you can create and manage orchestrator pools, configure pool settings and capabilities, and assign orchestrators to pools.

Tip:  Where to find this in the Management Portal:
Orchestrators → Management → Orchestrator Pool Management Tab