82ff1acf03
Instead of using the CA bundle, this sets HAProxy to use a specific file for validating the certificates of the services it's proxying. This helps in two ways: * Improves performance since validation will check only one certificate. * Improves security since we're only the certificates signed by one CA are valid, instead of any certificate that the system trusts (which could include potentially compromised public certs). Change-Id: Id6de045b3c93c82d37e0b0657c17a3108516016a |
||
---|---|---|
.. | ||
extraconfig | ||
manifests | ||
services | ||
all-nodes-config.yaml | ||
blockstorage-role.yaml | ||
cephstorage-role.yaml | ||
compute-role.yaml | ||
config.role.j2.yaml | ||
controller-role.yaml | ||
deploy-artifacts.sh | ||
deploy-artifacts.yaml | ||
major_upgrade_steps.j2.yaml | ||
objectstorage-role.yaml | ||
post-upgrade.j2.yaml | ||
post.j2.yaml | ||
puppet-steps.j2 | ||
role.role.j2.yaml | ||
upgrade_config.yaml |