Sync os cacert from proxy to salt master 87/40387/3
authorMichael Polenchuk <mpolenchuk@mirantis.com>
Mon, 28 Aug 2017 10:50:03 +0000 (14:50 +0400)
committerMichael Polenchuk <mpolenchuk@mirantis.com>
Mon, 28 Aug 2017 16:23:26 +0000 (20:23 +0400)
JIRA: FUEL-274
Change-Id: I2c8161b24cb18a0d1f9dc6fd509ce18af7ea8cf5
Signed-off-by: Michael Polenchuk <mpolenchuk@mirantis.com>
mcp/config/states/openstack_ha
mcp/patches/0008-Handle-file_recv-option.patch [new file with mode: 0644]
mcp/patches/patches.list
mcp/reclass/classes/cluster/baremetal-mcp-ocata-odl-ha/infra/config.yml
mcp/reclass/classes/cluster/baremetal-mcp-ocata-odl-ha/openstack/control.yml
mcp/reclass/classes/cluster/baremetal-mcp-ocata-ovs-dpdk-ha/infra/config.yml
mcp/reclass/classes/cluster/baremetal-mcp-ocata-ovs-dpdk-ha/openstack/control.yml
mcp/reclass/classes/cluster/baremetal-mcp-ocata-ovs-ha/infra/config.yml
mcp/reclass/classes/cluster/baremetal-mcp-ocata-ovs-ha/openstack/control.yml
mcp/reclass/classes/system

index 507ca61..cc4279c 100755 (executable)
@@ -44,3 +44,6 @@ salt -I 'nova:compute' state.sls nova
 
 salt -I 'horizon:server' state.sls horizon
 salt -I 'nginx:server' state.sls nginx
+
+salt -C 'I@nginx:server and *01*' cp.push /etc/ssl/certs/10.167.4.80-with-chain.crt upload_path='/os_cacert'
+cd /etc/ssl/certs && ln -s /var/cache/salt/master/minions/prx01.*/files/os_cacert
diff --git a/mcp/patches/0008-Handle-file_recv-option.patch b/mcp/patches/0008-Handle-file_recv-option.patch
new file mode 100644 (file)
index 0000000..0c76449
--- /dev/null
@@ -0,0 +1,18 @@
+From: Michael Polenchuk <mpolenchuk@mirantis.com>
+Date: Mon, 28 Aug 2017 16:17:43 +0400
+Subject: [PATCH] Handle file_recv option
+
+
+diff --git a/salt/files/master.conf b/salt/files/master.conf
+index 329ae0d..a9d9656 100644
+--- a/salt/files/master.conf
++++ b/salt/files/master.conf
+@@ -95,6 +95,8 @@ logstash_zmq_handler:
+ order_masters: True
+ {%- endif %}
+
++file_recv: {{ master.get('file_recv', False) }}
++
+ {#-
+ vim: syntax=jinja
+ -#}
index 1a651cf..419ff26 100644 (file)
@@ -5,3 +5,4 @@
 /usr/share/salt-formulas/env: 0005-maas-module-Obtain-fabric-ID-from-CIDR.patch
 /usr/share/salt-formulas/env: 0006-maas-module-Add-VLAN-DHCP-enable-support.patch
 /usr/share/salt-formulas/env: 0007-linux.network.interface-noifupdown-support.patch
+/usr/share/salt-formulas/env: 0008-Handle-file_recv-option.patch
index 202799f..a7b08f8 100644 (file)
@@ -38,6 +38,7 @@ parameters:
   salt:
     master:
       accept_policy: open_mode
+      file_recv: true
   reclass:
     storage:
       data_source:
index 227c649..e8666d6 100644 (file)
@@ -39,6 +39,9 @@ parameters:
       interface:
         ens2: ${_param:linux_dhcp_interface}
         ens3: ${_param:linux_single_interface}
+  keystone:
+    server:
+      cacert: /etc/ssl/certs/mcp_os_cacert
   neutron:
     server:
       backend:
index b7fd128..be3dc38 100644 (file)
@@ -37,6 +37,7 @@ parameters:
   salt:
     master:
       accept_policy: open_mode
+      file_recv: true
   reclass:
     storage:
       data_source:
index 4bfd27c..e7a3b85 100644 (file)
@@ -43,6 +43,9 @@ parameters:
       interface:
         ens2: ${_param:linux_dhcp_interface}
         ens3: ${_param:linux_single_interface}
+  keystone:
+    server:
+      cacert: /etc/ssl/certs/mcp_os_cacert
   bind:
     server:
       control:
index ce2c951..a75b41d 100644 (file)
@@ -37,6 +37,7 @@ parameters:
   salt:
     master:
       accept_policy: open_mode
+      file_recv: true
   reclass:
     storage:
       data_source:
index 6f47f8a..a5913dd 100644 (file)
@@ -39,6 +39,9 @@ parameters:
       interface:
         ens2: ${_param:linux_dhcp_interface}
         ens3: ${_param:linux_single_interface}
+  keystone:
+    server:
+      cacert: /etc/ssl/certs/mcp_os_cacert
   bind:
     server:
       control:
index fc30e31..7b186ff 160000 (submodule)
@@ -1 +1 @@
-Subproject commit fc30e3196598bb01f8807d90113d7b8c0794ea94
+Subproject commit 7b186ff21829b6a0055c08cc681b94bd89aedf1d