1 heat_template_version: pike
4 Contains a static list of common things necessary for containers
11 description: Mapping of service endpoint -> protocol. Typically set
12 via parameter_defaults in the resource registry.
16 description: Mapping of service_name -> network name. Typically set
17 via parameter_defaults in the resource registry. This
18 mapping overrides those in ServiceNetMapDefaults.
25 description: Role name on which the service is applied
29 description: Parameters specific to the role
37 default: '/etc/ipa/ca.crt'
39 description: Specifies the default CA cert to use if TLS is used for
40 services in the internal network.
44 internal_tls_enabled: {equals: [{get_param: EnableInternalTLS}, true]}
48 description: Common volumes for the containers.
51 - - /etc/hosts:/etc/hosts:ro
52 - /etc/localtime:/etc/localtime:ro
53 # required for bootstrap_host_exec
54 - /etc/puppet:/etc/puppet:ro
56 - /etc/pki/ca-trust/extracted:/etc/pki/ca-trust/extracted:ro
57 - /etc/pki/tls/certs/ca-bundle.crt:/etc/pki/tls/certs/ca-bundle.crt:ro
58 - /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/certs/ca-bundle.trust.crt:ro
59 - /etc/pki/tls/cert.pem:/etc/pki/tls/cert.pem:ro
62 - /etc/ssh/ssh_known_hosts:/etc/ssh/ssh_known_hosts:ro
64 - internal_tls_enabled
65 - - {get_param: InternalTLSCAFile}