Merge "Trust infracloud directly using public cert"

This commit is contained in:
Jenkins 2017-08-28 16:39:02 +00:00 committed by Gerrit Code Review
commit 6e97b65f3d
3 changed files with 24 additions and 8 deletions

View File

@ -171,6 +171,22 @@ node 'puppetmaster.openstack.org' {
mqtt_password => hiera('mqtt_service_user_password'), mqtt_password => hiera('mqtt_service_user_password'),
mqtt_ca_cert_contents => hiera('mosquitto_tls_ca_file'), mqtt_ca_cert_contents => hiera('mosquitto_tls_ca_file'),
} }
file { '/etc/openstack/infracloud_vanilla_cacert.pem':
ensure => present,
owner => 'root',
group => 'root',
mode => '0444',
content => hiera('infracloud_vanilla_ssl_cert_file_contents'),
require => Class['::openstack_project::puppetmaster'],
}
file { '/etc/openstack/infracloud_chocolate_cacert.pem':
ensure => present,
owner => 'root',
group => 'root',
mode => '0444',
content => hiera('infracloud_chocolate_ssl_cert_file_contents'),
require => Class['::openstack_project::puppetmaster'],
}
} }
# Node-OS: trusty # Node-OS: trusty

View File

@ -9,7 +9,7 @@ clouds:
project_domain_name: default project_domain_name: default
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_vanilla_cacert.pem
admin-infracloud-chocolate: admin-infracloud-chocolate:
region_name: RegionOne region_name: RegionOne
auth: auth:
@ -20,7 +20,7 @@ clouds:
project_domain_name: default project_domain_name: default
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_chocolate_cacert.pem
infra-files-ro: infra-files-ro:
profile: rackspace profile: rackspace
auth: auth:
@ -46,7 +46,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackci-infracloud-chocolate: openstackci-infracloud-chocolate:
region_name: RegionOne region_name: RegionOne
auth: auth:
@ -58,7 +58,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackci-internap: openstackci-internap:
profile: internap profile: internap
auth: auth:
@ -152,7 +152,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackzuul-infracloud-chocolate: openstackzuul-infracloud-chocolate:
region_name: RegionOne region_name: RegionOne
auth: auth:
@ -164,7 +164,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackjenkins-rax: openstackjenkins-rax:
regions: regions:
- DFW - DFW

View File

@ -90,7 +90,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackci-infracloud-chocolate: openstackci-infracloud-chocolate:
region_name: RegionOne region_name: RegionOne
auth: auth:
@ -102,7 +102,7 @@ clouds:
user_domain_name: default user_domain_name: default
identity_api_version: '3' identity_api_version: '3'
floating_ip_source: None floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackci-citycloud: openstackci-citycloud:
regions: regions:
- Lon1 - Lon1