Add kerberos-client group

We duplicate the KDC settings over all our kerberos clients.  Add
clients to a "kerberos-client" group and set the variables in a group
file.

Change-Id: I25ed5f8c68065060205dfbb634c6558488003a38
This commit is contained in:
Ian Wienand 2021-03-18 09:59:46 +11:00
parent 75a64427a1
commit dc827de23d
7 changed files with 16 additions and 20 deletions

View File

@ -0,0 +1,5 @@
kerberos_realm: 'OPENSTACK.ORG'
kerberos_admin_server: 'kdc.openstack.org'
kerberos_kdcs:
- kdc03.openstack.org
- kdc04.openstack.org

View File

@ -72,6 +72,14 @@ groups:
- health[0-9]*.openstack.org - health[0-9]*.openstack.org
jvb: jvb:
- jvb[0-9]*.opendev.org - jvb[0-9]*.opendev.org
kerberos-client:
- afs[0-9]*.open*.org
- afsdb*.open*.org
- kdc[0-9]*.openstack.org
- mirror[0-9]*.opendev.org
- mirror-update[0-9]*.opendev.org
- static[0-9]*.opendev.org
- ze[0-9]*.open*.org
kerberos-kdc: kerberos-kdc:
- kdc03.openstack.org - kdc03.openstack.org
- kdc04.openstack.org - kdc04.openstack.org

View File

@ -11,6 +11,7 @@ results:
- afs-server-common - afs-server-common
- afs-file-server - afs-file-server
- afs-client - afs-client
- kerberos-client
firehose01.openstack.org: firehose01.openstack.org:
- firehose - firehose
@ -34,6 +35,7 @@ results:
mirror02.regionone.linaro-us.opendev.org: mirror02.regionone.linaro-us.opendev.org:
- afs-client - afs-client
- kerberos-client
- letsencrypt - letsencrypt
- mirror - mirror
@ -48,6 +50,7 @@ results:
ze01.opendev.org: ze01.opendev.org:
- afs-client - afs-client
- kerberos-client
- zuul - zuul
- zuul-executor - zuul-executor

View File

@ -3,11 +3,6 @@
roles: roles:
- role: iptables - role: iptables
- role: kerberos-client - role: kerberos-client
kerberos_realm: 'OPENSTACK.ORG'
kerberos_admin_server: 'kdc.openstack.org'
kerberos_kdcs:
- kdc03.openstack.org
- kdc04.openstack.org
- role: openafs-client - role: openafs-client
openafs_client_cache_size: "{{ afs_client_cache_size | default(10000000) }}" # 10GiB openafs_client_cache_size: "{{ afs_client_cache_size | default(10000000) }}" # 10GiB
- role: mirror-update - role: mirror-update

View File

@ -3,11 +3,6 @@
roles: roles:
- role: iptables - role: iptables
- role: kerberos-client - role: kerberos-client
kerberos_realm: 'OPENSTACK.ORG'
kerberos_admin_server: 'kdc.openstack.org'
kerberos_kdcs:
- kdc03.openstack.org
- kdc04.openstack.org
- role: openafs-client - role: openafs-client
openafs_client_cache_size: "{{ afs_client_cache_size | default(50000000) }}" # 50GiB openafs_client_cache_size: "{{ afs_client_cache_size | default(50000000) }}" # 50GiB
- role: mirror - role: mirror

View File

@ -3,11 +3,6 @@
roles: roles:
- role: iptables - role: iptables
- role: kerberos-client - role: kerberos-client
kerberos_realm: 'OPENSTACK.ORG'
kerberos_admin_server: 'kdc.openstack.org'
kerberos_kdcs:
- kdc03.openstack.org
- kdc04.openstack.org
- role: openafs-client - role: openafs-client
openafs_client_cache_size: "{{ afs_client_cache_size | default(50000000) }}" # 50GiB openafs_client_cache_size: "{{ afs_client_cache_size | default(50000000) }}" # 50GiB
openafs_client_cache_directory: '/opt/cache/openafs' openafs_client_cache_directory: '/opt/cache/openafs'

View File

@ -24,11 +24,6 @@
name: "Configure zuul executor" name: "Configure zuul executor"
roles: roles:
- role: kerberos-client - role: kerberos-client
kerberos_realm: 'OPENSTACK.ORG'
kerberos_admin_server: 'kdc.openstack.org'
kerberos_kdcs:
- kdc03.openstack.org
- kdc04.openstack.org
- role: openafs-client - role: openafs-client
openafs_client_cache_size: "{{ afs_client_cache_size | default(10000000) }}" # 10GiB openafs_client_cache_size: "{{ afs_client_cache_size | default(10000000) }}" # 10GiB
- role: zuul-executor - role: zuul-executor