Turn off default apache ports 71/60971/1
authorMichael Polenchuk <mpolenchuk@mirantis.com>
Wed, 15 Aug 2018 10:07:32 +0000 (14:07 +0400)
committerMichael Polenchuk <mpolenchuk@mirantis.com>
Wed, 15 Aug 2018 10:07:32 +0000 (14:07 +0400)
Change-Id: I0377615ff19e39aca74b90d2ff7e7b2cd5cd6ccb
Signed-off-by: Michael Polenchuk <mpolenchuk@mirantis.com>
mcp/config/states/openstack_ha
mcp/config/states/openstack_noha
mcp/reclass/classes/cluster/mcp-common-ha/openstack_control.yml.j2
mcp/reclass/classes/cluster/mcp-common-ha/openstack_proxy.yml.j2
mcp/reclass/classes/cluster/mcp-common-ha/openstack_telemetry.yml.j2
mcp/reclass/classes/cluster/mcp-common-noha/openstack_control.yml

index 12d6ae6..d7d8cbd 100755 (executable)
@@ -68,7 +68,7 @@ salt -I 'aodh:server' state.sls aodh -b 1
 salt -I 'ceilometer:server' state.sls ceilometer
 salt -I 'ceilometer:agent' state.sls ceilometer
 
-salt -I 'horizon:server' state.sls horizon
+salt -I 'horizon:server' state.sls apache,horizon
 salt -I 'nginx:server' state.sls nginx
 
 cluster_public_host=$(salt -C 'I@nginx:server and *01*' --out=yaml \
index 0253023..9a42d48 100755 (executable)
@@ -56,4 +56,4 @@ salt -I 'aodh:server' state.sls aodh
 salt -I 'ceilometer:server' state.sls ceilometer
 salt -I 'ceilometer:agent' state.sls ceilometer
 
-salt -I 'horizon:server' state.sls horizon
+salt -I 'horizon:server' state.sls apache,horizon
index 33c74fd..f9fe73a 100644 (file)
@@ -23,6 +23,7 @@ classes:
   - system.barbican.server.cluster
   - system.apache.server.site.barbican
   - service.barbican.server.plugin.simple_crypto
+  - system.apache.server.single
   - system.bind.server.single
   - system.haproxy.proxy.listen.openstack.placement
   - system.glusterfs.client.cluster
@@ -125,7 +126,7 @@ parameters:
   apache:
     server:
       bind:
-        ~ports: ~
+        listen_default_ports: false
   # sync from common-ha kvm role
   glusterfs:
     server:
index d7ccff5..c23b509 100644 (file)
@@ -14,6 +14,7 @@ classes:
   - system.nginx.server.proxy.openstack_web
   - system.nginx.server.proxy.openstack.aodh
   - system.nginx.server.proxy.openstack.ceilometer
+  - system.apache.server.single
   - system.horizon.server.single
   - system.salt.minion.cert.proxy
   - system.sphinx.server.doc.reclass
@@ -93,3 +94,7 @@ parameters:
       vrrp_scripts:
         check_pidof:
           args: 'nginx'
+  apache:
+    server:
+      bind:
+        listen_default_ports: false
index c55ea00..9a9144c 100644 (file)
@@ -69,6 +69,8 @@ parameters:
         - python-memcache
   apache:
     server:
+      bind:
+        listen_default_ports: false
       ~modules:
         - rewrite
 {%- if conf.MCP_VCP %} {#- wsgi module will be enabled by a different class inherited later #}
index 0eeff7c..8ba9c69 100644 (file)
@@ -60,6 +60,7 @@ classes:
   - system.apache.server.site.gnocchi
   - system.apache.server.site.panko
   - system.apache.server.site.barbican
+  - system.apache.server.single
   - system.horizon.server.single
   - service.haproxy.proxy.single
   - cluster.mcp-common-noha.haproxy_openstack_api
@@ -174,6 +175,8 @@ parameters:
       root_helper_daemon: false
   apache:
     server:
+      bind:
+        listen_default_ports: false
       site:
         gnocchi: &wsgi_threads
           wsgi: