Unset Keystone public_endpoint
authorAdam Young <ayoung@redhat.com>
Mon, 12 Sep 2016 16:43:39 +0000 (12:43 -0400)
committerAdam Young <ayoung@redhat.com>
Mon, 12 Sep 2016 16:43:39 +0000 (12:43 -0400)
The keystone public_endpoint value should be deduced from the calling
request and not hardcoded, or it makes network isolation impossible.

Change-Id: Ide6a65aa9393cb84591b0015ec5966cc01ffbcf8
Closes-Bug: 1381961

puppet/services/keystone.yaml

index 7903304..6e94e4c 100644 (file)
@@ -136,7 +136,6 @@ outputs:
             keystone::endpoint::admin_url: {get_param: [EndpointMap, KeystoneAdmin, uri_no_suffix]}
             keystone::endpoint::region: {get_param: KeystoneRegion}
             keystone_enable_db_purge: {get_param: KeystoneEnableDBPurge}
-            keystone::public_endpoint: {get_param: [EndpointMap, KeystonePublic, uri_no_suffix]}
             keystone::db::mysql::user: keystone
             keystone::db::mysql::host: {get_param: [EndpointMap, MysqlInternal, host_nobrackets]}
             keystone::db::mysql::dbname: keystone