etcd: secure EtcdInitialClusterToken parameter
authorEmilien Macchi <emilien@redhat.com>
Wed, 15 Mar 2017 21:56:30 +0000 (17:56 -0400)
committerEmilien Macchi <emilien@redhat.com>
Wed, 15 Mar 2017 21:58:27 +0000 (17:58 -0400)
Secure EtcdInitialClusterToken parameter by:

* removing the default value.
* make it hidden.

Change-Id: I938af697f9faaadb9c9aeb950e9410db24b1b961
Depends-On: I6e30cce469736e84a3c483fafa29d542b8347ba9
Closes-Bug: #1673266

puppet/services/etcd.yaml
releasenotes/notes/etcdtoken-4c46bdfac940acda.yaml [new file with mode: 0644]

index 7cdd845..5db8bec 100644 (file)
@@ -19,9 +19,9 @@ parameters:
                  via parameter_defaults in the resource registry.
     type: json
   EtcdInitialClusterToken:
-    default: 'etcd-tripleo'
     description: Initial cluster token for the etcd cluster during bootstrap.
     type: string
+    hidden: true
   MonitoringSubscriptionEtcd:
     default: 'overcloud-etcd'
     type: string
diff --git a/releasenotes/notes/etcdtoken-4c46bdfac940acda.yaml b/releasenotes/notes/etcdtoken-4c46bdfac940acda.yaml
new file mode 100644 (file)
index 0000000..da99594
--- /dev/null
@@ -0,0 +1,6 @@
+---
+security:
+  - |
+    Secure EtcdInitialClusterToken by removing the default value
+    and make the parameter hidden.
+    Fixes `bug 1673266 <https://bugs.launchpad.net/tripleo/+bug/1673266>`__.