X-Git-Url: https://gerrit.akraino.org/r/gitweb?a=blobdiff_plain;f=ocd%2Finfra%2Fplaybooks%2Froles%2Fmepserver%2Ftasks%2Finstall.yml;h=01c3f67826920ec570825e0c13f7529790b936c3;hb=b53813aee440d6c0a936a2827e5c304cf60d8be1;hp=b739ae2798ebe9e2e7fc9013936ec75b71b1497e;hpb=b747fd2db81a059a8fa8e3acb23ca2c5980fc93b;p=ealt-edge.git diff --git a/ocd/infra/playbooks/roles/mepserver/tasks/install.yml b/ocd/infra/playbooks/roles/mepserver/tasks/install.yml index b739ae2..01c3f67 100644 --- a/ocd/infra/playbooks/roles/mepserver/tasks/install.yml +++ b/ocd/infra/playbooks/roles/mepserver/tasks/install.yml @@ -23,47 +23,6 @@ src: deploy dest: /tmp/mepserver/ -- name: Generate Certificates - shell: -# yamllint disable rule:line-length - cmd: openssl genrsa -out ca.key 2048 - chdir: /tmp/mepserver/deploy/ - -- name: Generate Certificate - Step 2 - shell: - cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr - chdir: /tmp/mepserver/deploy/ - -- name: Generate Root Certificate - shell: - cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS certificate and TLS Key - shell: - cmd: openssl genrsa -out server_key.pem 2048 - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS Certificate and TLS Key - shell: - cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr - chdir: /tmp/mepserver/deploy/ - -- name: Generate TLS Certificate and TLS Key - shell: - cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer - chdir: /tmp/mepserver/deploy/ - -- name: Create mepssl-secret - shell: -# yamllint disable rule:line-length - cmd: kubectl create secret --namespace mep generic mepssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer - -- name: Create kongssl-secret - shell: -# yamllint disable rule:line-length - cmd: kubectl create secret --namespace mep generic kongssl-secret --from-file=/tmp/mepserver/deploy/server.cer --from-file=/tmp/mepserver/deploy/server_key.pem --from-file=/tmp/mepserver/deploy/trust.cer - - name: Apply mep-basic.yaml shell: cmd: kubectl apply -f /tmp/mepserver/deploy/mep-basic.yaml