Merge "Trust infracloud directly using public cert"

This commit is contained in:
Jenkins 2017-08-28 16:39:02 +00:00 committed by Gerrit Code Review
commit 6e97b65f3d
3 changed files with 24 additions and 8 deletions

View File

@ -171,6 +171,22 @@ node 'puppetmaster.openstack.org' {
mqtt_password => hiera('mqtt_service_user_password'),
mqtt_ca_cert_contents => hiera('mosquitto_tls_ca_file'),
}
file { '/etc/openstack/infracloud_vanilla_cacert.pem':
ensure => present,
owner => 'root',
group => 'root',
mode => '0444',
content => hiera('infracloud_vanilla_ssl_cert_file_contents'),
require => Class['::openstack_project::puppetmaster'],
}
file { '/etc/openstack/infracloud_chocolate_cacert.pem':
ensure => present,
owner => 'root',
group => 'root',
mode => '0444',
content => hiera('infracloud_chocolate_ssl_cert_file_contents'),
require => Class['::openstack_project::puppetmaster'],
}
}
# Node-OS: trusty

View File

@ -9,7 +9,7 @@ clouds:
project_domain_name: default
user_domain_name: default
identity_api_version: '3'
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
admin-infracloud-chocolate:
region_name: RegionOne
auth:
@ -20,7 +20,7 @@ clouds:
project_domain_name: default
user_domain_name: default
identity_api_version: '3'
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
infra-files-ro:
profile: rackspace
auth:
@ -46,7 +46,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackci-infracloud-chocolate:
region_name: RegionOne
auth:
@ -58,7 +58,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackci-internap:
profile: internap
auth:
@ -152,7 +152,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackzuul-infracloud-chocolate:
region_name: RegionOne
auth:
@ -164,7 +164,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackjenkins-rax:
regions:
- DFW

View File

@ -90,7 +90,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_vanilla_cacert.pem
openstackci-infracloud-chocolate:
region_name: RegionOne
auth:
@ -102,7 +102,7 @@ clouds:
user_domain_name: default
identity_api_version: '3'
floating_ip_source: None
cacert: /etc/ssl/certs/ca-certificates.crt
cacert: /etc/openstack/infracloud_chocolate_cacert.pem
openstackci-citycloud:
regions:
- Lon1