Merge "Turn off the etcd TLS workaround used with novajoin"

This commit is contained in:
Zuul 2021-01-20 23:44:02 +00:00 committed by Gerrit Code Review
commit f7158d5899
4 changed files with 27 additions and 3 deletions

View File

@ -72,7 +72,7 @@ parameters:
for cinder's lock manager, even when the rest of the internal
API network is using TLS.
type: boolean
default: false
default: true
CephConfigPath:
type: string
default: "/var/lib/tripleo-config/ceph"

View File

@ -175,7 +175,7 @@ parameters:
for cinder's lock manager, even when the rest of the internal
API network is using TLS.
type: boolean
default: false
default: true
CephConfigPath:
type: string
default: "/var/lib/tripleo-config/ceph"

View File

@ -51,7 +51,7 @@ parameters:
for cinder's lock manager, even when the rest of the internal
API network is using TLS.
type: boolean
default: false
default: true
InternalTLSCAFile:
default: '/etc/ipa/ca.crt'
type: string
@ -72,6 +72,16 @@ parameters:
description: Override the private key size used when creating the
certificate for this service
parameter_groups:
- label: deprecated
description: |
The following parameters are deprecated and will be removed. They should not
be relied on for new deployments. If you have concerns regarding deprecated
parameters, please contact the TripleO development team on IRC or the
OpenStack mailing list.
parameters:
- EnableEtcdInternalTLS
conditions:
internal_tls_enabled:
and:

View File

@ -0,0 +1,14 @@
---
upgrade:
- |
The `EnableEtcdInternalTLS` parameter's default value changes from false
to true. The change is related to the fact that novajoin is deprecated,
and the functionality associated with the `EnableEtcdInternalTLS` parameter
is not required when TLS is deployed using the tripleo-ansible ansible
module.
deprecations:
- |
The `EnableEtcdInternalTLS` parameter is deprecated. It was added to support
a workaround that is necessary when novajoin is used to deploy TLS, but
novajoin itself is deprecated. The workaround is not necessary when TLS
is deployed using the tripleo-ansible ansible module.