Add /etc/ssl/certs to trusted_ro_paths for zuul-executors

If we download things over HTTPs inside bwrap, we'll need access to
/etc/ssl/certs to validate certs.

Change-Id: Ib662afbc0e3375a2d461ef7fc6e7e4f8741a700c
Signed-off-by: Paul Belanger <pabelanger@redhat.com>
This commit is contained in:
Paul Belanger 2017-10-17 10:59:20 -04:00
parent f8c705f462
commit e65fc34af6
No known key found for this signature in database
GPG Key ID: 611A80832067AF38

View File

@ -1196,7 +1196,7 @@ node /^ze\d+\.openstack\.org$/ {
gearman_ssl_ca => hiera('gearman_ssl_ca'),
#TODO(pabelanger): Add openafs role for zuul-jobs to setup /etc/openafs
# properly. We need to revisting this post Queens PTG.
trusted_ro_paths => ['/etc/openafs', '/var/lib/zuul/ssh'],
trusted_ro_paths => ['/etc/openafs', '/etc/ssl/certs', '/var/lib/zuul/ssh'],
trusted_rw_paths => ['/afs'],
disk_limit_per_job => 5000, # Megabytes
site_variables_yaml_file => $::project_config::zuul_site_variables_yaml,