Add metadata settings for needed kerberos principals
authorJuan Antonio Osorio Robles <jaosorior@redhat.com>
Thu, 15 Dec 2016 14:20:40 +0000 (16:20 +0200)
committerJuan Antonio Osorio Robles <jaosorior@redhat.com>
Tue, 24 Jan 2017 22:33:11 +0000 (00:33 +0200)
commit80086fd342032ec448a84ecf7c5dbe98d381450a
tree401b9f6d0e6f80930c90a0a48bcd3c435a03b8e7
parent00938b0accff3a07954ff058e205f21a51583b56
Add metadata settings for needed kerberos principals

These are only used for TLS-everywhere, and fills up the kerberos
principals that will need to be created for the certs used by the
overcloud. With this, the metadata hook will format these principals
correctly and will further pass them on to the nova metadata service.
Where they can be used if there's a plugin enabled.

bp tls-via-certmonger
bp novajoin

Change-Id: I873094bb69200052febda629fda698a7a782c031
18 files changed:
extraconfig/nova_metadata/krb-service-principals.yaml [new file with mode: 0644]
puppet/services/aodh-api.yaml
puppet/services/apache-internal-tls-certmonger.yaml
puppet/services/apache.yaml
puppet/services/barbican-api.yaml
puppet/services/ceilometer-api.yaml
puppet/services/cinder-api.yaml
puppet/services/database/mysql-internal-tls-certmonger.yaml
puppet/services/database/mysql.yaml
puppet/services/gnocchi-api.yaml
puppet/services/haproxy-internal-tls-certmonger.yaml
puppet/services/haproxy-public-tls-certmonger.yaml
puppet/services/haproxy.yaml
puppet/services/keystone.yaml
puppet/services/nova-api.yaml
puppet/services/pacemaker/database/mysql.yaml
puppet/services/pacemaker/haproxy.yaml
puppet/services/panko-api.yaml