src: deploy
dest: /tmp/mepserver/
-- name: Generate Certificates
- shell:
-# yamllint disable rule:line-length
- cmd: openssl genrsa -out ca.key 2048
- chdir: /tmp/mepserver/deploy/
-
-- name: Generate Certificate - Step 2
- shell:
- cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr
- chdir: /tmp/mepserver/deploy/
-
-- name: Generate Root Certificate
- shell:
- cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer
- chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS certificate and TLS Key
- shell:
- cmd: openssl genrsa -out server_key.pem 2048
- chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS Certificate and TLS Key
- shell:
- cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr
- chdir: /tmp/mepserver/deploy/
-
-- name: Generate TLS Certificate and TLS Key
- shell:
- cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer
- chdir: /tmp/mepserver/deploy/
-
-- name: Create mepssl-secret
- shell:
-# yamllint disable rule:line-length
- cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
-
-- name: Create kongssl-secret
- shell:
-# yamllint disable rule:line-length
- cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer
-
- name: Apply mep-basic.yaml
shell:
cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml