Modified to support certificate generation 35/3635/1
authorabhijit_onap <abhijit.das.gupta@huawei.com>
Wed, 22 Jul 2020 07:06:57 +0000 (12:36 +0530)
committerabhijit_onap <abhijit.das.gupta@huawei.com>
Wed, 22 Jul 2020 07:08:20 +0000 (12:38 +0530)
Added steps to create Certificate and Key

Signed-off-by: abhijit_onap <abhijit.das.gupta@huawei.com>
Change-Id: I6c970c1e77a147655b79cdbf9512e3b0722fce03

ocd/infra/playbooks/roles/applcm/tasks/install.yml

index 12c7aa4..f907387 100644 (file)
     src: deploy
     dest: /tmp/applcm/
 
+- name: Generate Certificates
+  shell:
+# yamllint disable rule:line-length
+    cmd: openssl genrsa -out ca.key 2048
+    chdir: /tmp/applcm/deploy/
+
+- name: Generate Certificate - Step 2
+  shell:
+    cmd: openssl req -new -key ca.key -subj /C=CN/ST=Peking/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out ca.csr
+    chdir: /tmp/applcm/deploy/
+
+- name: Generate Root Certificate
+  shell:
+    cmd: openssl x509 -req -days 365 -in ca.csr -extensions v3_req -signkey ca.key -out trust.cer
+    chdir: /tmp/applcm/deploy/
+
+- name: Generate Server Key
+  shell:
+    cmd: openssl genrsa -out server_key.pem 2048
+    chdir: /tmp/applcm/deploy/
+
+
+- name: Generate Server CSR
+  shell:
+    cmd: openssl req -new -key server_key.pem -subj /C=CN/ST=Beijing/L=Beijing/O=ealtedge/CN=www.ealtedge.org -out tls.csr
+    chdir: /tmp/applcm/deploy/
+
+- name: Generate Server Certificate
+  shell:
+    cmd: openssl x509 -req -in tls.csr -extensions v3_req -CA trust.cer -CAkey ca.key -CAcreateserial -out server.cer
+    chdir: /tmp/applcm/deploy/
+
+- name: Create applcm-secret
+  shell:
+# yamllint disable rule:line-length
+    cmd: kubectl create secret --namespace default generic applcm-secret --from-file=/tmp/applcm/deploy/server.cer --from-file=/tmp/applcm/deploy/server_key.pem --from-file=/tmp/applcm/deploy/trust.cer
+
 - name: Install applcm postgres-configmap
   shell:
     cmd: kubectl apply -f /tmp/applcm/deploy/postgres-config.yaml