diff --git a/manifests/init.pp b/manifests/init.pp index e3431a1..e0f8353 100644 --- a/manifests/init.pp +++ b/manifests/init.pp @@ -151,10 +151,6 @@ # (Optional) Password for decrypting ssl_key_file (if encrypted) # Defaults to $::os_service_default. # -# [*amqp_allow_insecure_clients*] -# (Optional) Accept clients using either SSL or plain TCP -# Defaults to $::os_service_default. -# # [*amqp_sasl_mechanisms*] # (Optional) Space separated list of acceptable SASL mechanisms # Defaults to $::os_service_default. @@ -180,6 +176,12 @@ # in the magnum config. # Defaults to false. # +# DEPRECATED PARAMETERS +# +# [*amqp_allow_insecure_clients*] +# (Optional) Accept clients using either SSL or plain TCP +# Defaults to undef. +# class magnum( $package_ensure = 'present', $notification_transport_url = $::os_service_default, @@ -211,13 +213,14 @@ class magnum( $amqp_ssl_cert_file = $::os_service_default, $amqp_ssl_key_file = $::os_service_default, $amqp_ssl_key_password = $::os_service_default, - $amqp_allow_insecure_clients = $::os_service_default, $amqp_sasl_mechanisms = $::os_service_default, $amqp_sasl_config_dir = $::os_service_default, $amqp_sasl_config_name = $::os_service_default, $amqp_username = $::os_service_default, $amqp_password = $::os_service_default, $purge_config = false, + # DEPRECATED PARAMETERS + $amqp_allow_insecure_clients = undef, ) { include magnum::deps @@ -225,6 +228,11 @@ class magnum( include magnum::policy include magnum::db + if $amqp_allow_insecure_clients != undef { + warning('The amqp_allow_insecure_clients parameter is deprecated and \ +will be removed in a future release.') + } + package { 'magnum-common': ensure => $package_ensure, name => $::magnum::params::common_package, @@ -252,22 +260,21 @@ class magnum( } oslo::messaging::amqp { 'magnum_config': - server_request_prefix => $amqp_server_request_prefix, - broadcast_prefix => $amqp_broadcast_prefix, - group_request_prefix => $amqp_group_request_prefix, - container_name => $amqp_container_name, - idle_timeout => $amqp_idle_timeout, - trace => $amqp_trace, - ssl_ca_file => $amqp_ssl_ca_file, - ssl_cert_file => $amqp_ssl_cert_file, - ssl_key_file => $amqp_ssl_key_file, - ssl_key_password => $amqp_ssl_key_password, - allow_insecure_clients => $amqp_allow_insecure_clients, - sasl_mechanisms => $amqp_sasl_mechanisms, - sasl_config_dir => $amqp_sasl_config_dir, - sasl_config_name => $amqp_sasl_config_name, - username => $amqp_username, - password => $amqp_password, + server_request_prefix => $amqp_server_request_prefix, + broadcast_prefix => $amqp_broadcast_prefix, + group_request_prefix => $amqp_group_request_prefix, + container_name => $amqp_container_name, + idle_timeout => $amqp_idle_timeout, + trace => $amqp_trace, + ssl_ca_file => $amqp_ssl_ca_file, + ssl_cert_file => $amqp_ssl_cert_file, + ssl_key_file => $amqp_ssl_key_file, + ssl_key_password => $amqp_ssl_key_password, + sasl_mechanisms => $amqp_sasl_mechanisms, + sasl_config_dir => $amqp_sasl_config_dir, + sasl_config_name => $amqp_sasl_config_name, + username => $amqp_username, + password => $amqp_password, } oslo::messaging::default { 'magnum_config': diff --git a/releasenotes/notes/deprecate_allow_insecure_clients-option-974063e837f1b85f.yaml b/releasenotes/notes/deprecate_allow_insecure_clients-option-974063e837f1b85f.yaml new file mode 100644 index 0000000..72dff75 --- /dev/null +++ b/releasenotes/notes/deprecate_allow_insecure_clients-option-974063e837f1b85f.yaml @@ -0,0 +1,4 @@ +--- +deprecations: + - allow_insecure_clients option is now deprecated for removal, the + parameter has no effect. diff --git a/spec/classes/magnum_init_spec.rb b/spec/classes/magnum_init_spec.rb index 245b9ab..f8837e2 100644 --- a/spec/classes/magnum_init_spec.rb +++ b/spec/classes/magnum_init_spec.rb @@ -182,7 +182,6 @@ describe 'magnum' do :ssl_cert_file => '', :ssl_key_file => '', :ssl_key_password => '', - :allow_insecure_clients => '', :sasl_mechanisms => '', :sasl_config_dir => '', :sasl_config_name => '', @@ -216,7 +215,6 @@ describe 'magnum' do :ssl_cert_file => '/etc/certfile', :ssl_key_file => '/etc/key', :ssl_key_password => '', - :allow_insecure_clients => '', :sasl_mechanisms => '', :sasl_config_dir => '', :sasl_config_name => '',