Merge "Trust infracloud directly using public cert"
This commit is contained in:
commit
6e97b65f3d
@ -171,6 +171,22 @@ node 'puppetmaster.openstack.org' {
|
|||||||
mqtt_password => hiera('mqtt_service_user_password'),
|
mqtt_password => hiera('mqtt_service_user_password'),
|
||||||
mqtt_ca_cert_contents => hiera('mosquitto_tls_ca_file'),
|
mqtt_ca_cert_contents => hiera('mosquitto_tls_ca_file'),
|
||||||
}
|
}
|
||||||
|
file { '/etc/openstack/infracloud_vanilla_cacert.pem':
|
||||||
|
ensure => present,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0444',
|
||||||
|
content => hiera('infracloud_vanilla_ssl_cert_file_contents'),
|
||||||
|
require => Class['::openstack_project::puppetmaster'],
|
||||||
|
}
|
||||||
|
file { '/etc/openstack/infracloud_chocolate_cacert.pem':
|
||||||
|
ensure => present,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0444',
|
||||||
|
content => hiera('infracloud_chocolate_ssl_cert_file_contents'),
|
||||||
|
require => Class['::openstack_project::puppetmaster'],
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
# Node-OS: trusty
|
# Node-OS: trusty
|
||||||
|
@ -9,7 +9,7 @@ clouds:
|
|||||||
project_domain_name: default
|
project_domain_name: default
|
||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
|
||||||
admin-infracloud-chocolate:
|
admin-infracloud-chocolate:
|
||||||
region_name: RegionOne
|
region_name: RegionOne
|
||||||
auth:
|
auth:
|
||||||
@ -20,7 +20,7 @@ clouds:
|
|||||||
project_domain_name: default
|
project_domain_name: default
|
||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
|
||||||
infra-files-ro:
|
infra-files-ro:
|
||||||
profile: rackspace
|
profile: rackspace
|
||||||
auth:
|
auth:
|
||||||
@ -46,7 +46,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
|
||||||
openstackci-infracloud-chocolate:
|
openstackci-infracloud-chocolate:
|
||||||
region_name: RegionOne
|
region_name: RegionOne
|
||||||
auth:
|
auth:
|
||||||
@ -58,7 +58,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
|
||||||
openstackci-internap:
|
openstackci-internap:
|
||||||
profile: internap
|
profile: internap
|
||||||
auth:
|
auth:
|
||||||
@ -152,7 +152,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
|
||||||
openstackzuul-infracloud-chocolate:
|
openstackzuul-infracloud-chocolate:
|
||||||
region_name: RegionOne
|
region_name: RegionOne
|
||||||
auth:
|
auth:
|
||||||
@ -164,7 +164,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
|
||||||
openstackjenkins-rax:
|
openstackjenkins-rax:
|
||||||
regions:
|
regions:
|
||||||
- DFW
|
- DFW
|
||||||
|
@ -90,7 +90,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
|
||||||
openstackci-infracloud-chocolate:
|
openstackci-infracloud-chocolate:
|
||||||
region_name: RegionOne
|
region_name: RegionOne
|
||||||
auth:
|
auth:
|
||||||
@ -102,7 +102,7 @@ clouds:
|
|||||||
user_domain_name: default
|
user_domain_name: default
|
||||||
identity_api_version: '3'
|
identity_api_version: '3'
|
||||||
floating_ip_source: None
|
floating_ip_source: None
|
||||||
cacert: /etc/ssl/certs/ca-certificates.crt
|
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
|
||||||
openstackci-citycloud:
|
openstackci-citycloud:
|
||||||
regions:
|
regions:
|
||||||
- Lon1
|
- Lon1
|
||||||
|
Loading…
x
Reference in New Issue
Block a user