Browse Source
All of the other SSL environments were converted, but this one was missed. That's an inconsistent user experience and should be cleaned up. This environment also exposed a bug in the tool where it did not include the parameter_defaults section key if all the parameters were marked static. Change-Id: I19bc422c22b9f60f781e696ce703b026dc317786 Closes-Bug: 1713761changes/46/493246/2
4 changed files with 75 additions and 1 deletions
@ -0,0 +1,36 @@
|
||||
# ******************************************************************* |
||||
# This file was created automatically by the sample environment |
||||
# generator. Developers should use `tox -e genconfig` to update it. |
||||
# Users are recommended to make changes to a copy of the file instead |
||||
# of the original, if any customizations are needed. |
||||
# ******************************************************************* |
||||
# title: Enable SSL on OpenStack Internal Endpoints |
||||
# description: | |
||||
# A Heat environment file which can be used to enable TLS for the internal |
||||
# network via certmonger |
||||
parameter_defaults: |
||||
# ****************************************************** |
||||
# Static parameters - these are values that must be |
||||
# included in the environment but should not be changed. |
||||
# ****************************************************** |
||||
# |
||||
# Type: boolean |
||||
EnableInternalTLS: True |
||||
|
||||
# Rabbit client subscriber parameter to specify an SSL connection to the RabbitMQ host. |
||||
# Type: string |
||||
RabbitClientUseSSL: True |
||||
|
||||
# Extra properties or metadata passed to Nova for the created nodes in the overcloud. It's accessible via the Nova metadata API. |
||||
# Type: json |
||||
ServerMetadata: |
||||
ipa_enroll: True |
||||
|
||||
# ********************* |
||||
# End static parameters |
||||
# ********************* |
||||
resource_registry: |
||||
OS::TripleO::ServiceServerMetadataHook: ../extraconfig/nova_metadata/krb-service-principals.yaml |
||||
OS::TripleO::Services::CertmongerUser: ../puppet/services/certmonger-user.yaml |
||||
OS::TripleO::Services::HAProxyInternalTLS: ../puppet/services/haproxy-internal-tls-certmonger.yaml |
||||
OS::TripleO::Services::TLSProxyBase: ../puppet/services/apache.yaml |
Loading…
Reference in new issue