Bind mount needed cert for haproxy for HA too
[apex-tripleo-heat-templates.git] / docker / services / swift-proxy.yaml
index 988bb39..d7a7fe4 100644 (file)
@@ -12,6 +12,10 @@ parameters:
     description: image
     default: 'centos-binary-swift-proxy-server:latest'
     type: string
+  DockerSwiftConfigImage:
+    description: The container image to use for the swift config_volume
+    default: 'centos-binary-swift-proxy-server:latest'
+    type: string
   EndpointMap:
     default: {}
     description: Mapping of service endpoint -> protocol. Typically set
@@ -33,6 +37,7 @@ parameters:
   RoleParameters:
     default: {}
     description: Parameters specific to the role
+    type: json
   EnableInternalTLS:
     type: boolean
     default: false
@@ -69,10 +74,10 @@ outputs:
         config_volume: swift
         puppet_tags: swift_proxy_config
         step_config: *step_config
-        config_image: &swift_proxy_image
+        config_image:
           list_join:
             - '/'
-            - [ {get_param: DockerNamespace}, {get_param: DockerSwiftProxyImage} ]
+            - [ {get_param: DockerNamespace}, {get_param: DockerSwiftConfigImage} ]
       kolla_config:
         /var/lib/kolla/config_files/swift_proxy.json:
           command: /usr/bin/swift-proxy-server /etc/swift/proxy-server.conf
@@ -86,7 +91,10 @@ outputs:
         step_4:
           map_merge:
             - swift_proxy:
-                image: *swift_proxy_image
+                image: &swift_proxy_image
+                  list_join:
+                    - '/'
+                    - [ {get_param: DockerNamespace}, {get_param: DockerSwiftProxyImage} ]
                 net: host
                 user: swift
                 restart: always
@@ -116,7 +124,9 @@ outputs:
                         - {get_attr: [ContainersCommon, volumes]}
                         -
                           - /var/lib/kolla/config_files/swift_proxy_tls_proxy.json:/var/lib/kolla/config_files/config.json:ro
-                          - /var/lib/config-data/swift/etc/httpd/:/etc/httpd/:ro
+                          - /var/lib/config-data/swift/etc/httpd/conf/:/etc/httpd/conf/:ro
+                          - /var/lib/config-data/swift/etc/httpd/conf.d/:/etc/httpd/conf.d/:ro
+                          - /var/lib/config-data/swift/etc/httpd/conf.modules.d/:/etc/httpd/conf.modules.d/:ro
                           - /etc/pki/tls/certs/httpd:/etc/pki/tls/certs/httpd:ro
                           - /etc/pki/tls/private/httpd:/etc/pki/tls/private/httpd:ro
                     environment:
@@ -134,3 +144,5 @@ outputs:
         - name: Stop and disable swift_proxy service
           tags: step2
           service: name=openstack-swift-proxy state=stopped enabled=no
+      metadata_settings:
+        get_attr: [SwiftProxyBase, role_data, metadata_settings]