tripleo-heat-templates/environments/ssl
Ade Lee ae68c90b92 Add new composable service for IpaClient
This new role is used to register nodes as ipa-clients and
configure the services required in IPA using ansible, rather
than using novajoin.  This is required on the standalone
environment, where there is no novajoin. It will also be the
implementation used when nova is removed from the undercloud
and for pre-provisioned nodes. The existing IpaClient
composable service will be removed in a future release.

This code replaces the server ipaclient-baremetal-ansible by using
a role from freeipa-ansible to register the nodes (controllers,
computes) as ipa-clients.

In external_tasks, the host entry is created and an otp is stored
as a host variable.  In deploy_step_tasks, this otp is used to
register the node. The IPA configuration tasks are delegated to
http://opendev.org/x/tripleo-ipa roles.

Co-Authored-By: Grzegorz Grasza <xek@redhat.com>
Change-Id: I7dcd4608d3998596c2e4da19a8eca0d48e1fa841
2020-04-01 16:27:49 +02:00
..
enable-internal-tls.j2.yaml Add new composable service for IpaClient 2020-04-01 16:27:49 +02:00
enable-tls.yaml Add HorizonSecureCookies to environments/ssl/enable-tls.yaml 2019-01-17 14:40:49 +02:00
inject-trust-anchor-hiera.yaml Add nested sample environments for inject-trust-anchor 2017-06-12 15:02:50 -05:00
inject-trust-anchor.yaml Add nested sample environments for inject-trust-anchor 2017-06-12 15:02:50 -05:00
no-tls-endpoints-public-ip.yaml Add the certificate specs in ceph_mgr service 2020-03-05 06:55:14 +00:00
tls-endpoints-public-dns.yaml Add the certificate specs in ceph_mgr service 2020-03-05 06:55:14 +00:00
tls-endpoints-public-ip.yaml Add the certificate specs in ceph_mgr service 2020-03-05 06:55:14 +00:00
tls-everywhere-endpoints-dns.yaml Add the certificate specs in ceph_mgr service 2020-03-05 06:55:14 +00:00