59d7af0e67
This adds roles that, similar to add-build-sshkey, create a per-build WinRM certificate, install it on remote windows nodes, and then switch to using the certificate in Ansible for authentication. A second role is included which can clean up the cert which is useful for static nodes. Since winrm certificates must be acessible within the bubblewrap container, these roles can be used to restrict the system-wide winrm cert to trusted playbooks while untrusted playbooks will only have access to the per-build cert (with appropriate configuration of the executor). Change-Id: I4efe25594c2f543886a000aa02fb0a38683a43cb
5 lines
192 B
ReStructuredText
5 lines
192 B
ReStructuredText
Remove the per-build WinRM certificate from all hosts
|
|
|
|
The complement to :zuul:role:`add-build-winrm-cert`. It removes the
|
|
build's WinRM certificate from WSMan registry of all Windows hosts.
|