CN added for all etcd certs 65/1265/1
authorBalint Varga <balint.varga@nokia.com>
Fri, 26 Jul 2019 07:12:58 +0000 (09:12 +0200)
committerBalint Varga <balint.varga@nokia.com>
Fri, 26 Jul 2019 07:12:58 +0000 (09:12 +0200)
Signed-off-by: Balint Varga <balint.varga@nokia.com>
Change-Id: I0f3add64ca03a6a0d37235fbf911d9a593c0ff60

ansible/roles/etcd/meta/main.yml
ansible/roles/etcd/tasks/add_member.yml
ansible/roles/etcd/tasks/main.yml
ansible/roles/etcd/tasks/try_add_member.yml
caas-etcd.spec

index 3c55c93..cc3cd71 100644 (file)
@@ -49,6 +49,7 @@ dependencies:
   - role: cert
     instance: "etcd{{ nodeindex }}"
     cert_path: /etc/etcd/ssl
   - role: cert
     instance: "etcd{{ nodeindex }}"
     cert_path: /etc/etcd/ssl
+    common_name: "etcd"
     alt_names:
       ip:
         "{{ lookup('template', 'caas-master-nodes.j2') | from_yaml }}"
     alt_names:
       ip:
         "{{ lookup('template', 'caas-master-nodes.j2') | from_yaml }}"
index f33c541..cc40614 100644 (file)
@@ -38,7 +38,7 @@
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
-    DOCKER_CERT_PATH: "/etc/docker"
+    DOCKER_CERT_PATH: "{{ caas.cert_directory }}"
   register: etcd_container_id_add_member
   until: etcd_container_id_add_member.stdout
   retries: 50
   register: etcd_container_id_add_member
   until: etcd_container_id_add_member.stdout
   retries: 50
index 3c0636f..2425776 100644 (file)
@@ -54,7 +54,7 @@
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
-    DOCKER_CERT_PATH: "/etc/docker"
+    DOCKER_CERT_PATH: "{{ caas.cert_directory }}"
   register: etcd_container_id
   until: etcd_container_id.stdout
   delay: 5
   register: etcd_container_id
   until: etcd_container_id.stdout
   delay: 5
@@ -65,7 +65,7 @@
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
-    DOCKER_CERT_PATH: "/etc/docker"
+    DOCKER_CERT_PATH: "{{ caas.cert_directory }}"
   register: result
   until: result.stdout|int == master_list|length|int
   delay: 5
   register: result
   until: result.stdout|int == master_list|length|int
   delay: 5
index 15b2aed..2abdbc9 100644 (file)
@@ -18,7 +18,7 @@
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
-    DOCKER_CERT_PATH: "/etc/docker"
+    DOCKER_CERT_PATH: "{{ caas.cert_directory }}"
   register: member_add_result
   until: (member_add_result.stdout.find("exists") != -1 ) or (member_add_result.stdout.find("added") != -1 )
   delay: 10
   register: member_add_result
   until: (member_add_result.stdout.find("exists") != -1 ) or (member_add_result.stdout.find("added") != -1 )
   delay: 10
@@ -29,7 +29,7 @@
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
   environment:
     DOCKER_HOST: "tcp://{{ networking.infra_internal.ip }}:2375"
     DOCKER_TLS_VERIFY: "1"
-    DOCKER_CERT_PATH: "/etc/docker"
+    DOCKER_CERT_PATH: "{{ caas.cert_directory }}"
   register: addresult
 
 - set_fact:
   register: addresult
 
 - set_fact:
index 0a80f02..34cbdad 100644 (file)
@@ -15,7 +15,7 @@
 %define COMPONENT etcd
 %define RPM_NAME caas-%{COMPONENT}
 %define RPM_MAJOR_VERSION 3.3.13
 %define COMPONENT etcd
 %define RPM_NAME caas-%{COMPONENT}
 %define RPM_MAJOR_VERSION 3.3.13
-%define RPM_MINOR_VERSION 4
+%define RPM_MINOR_VERSION 5
 %define IMAGE_TAG %{RPM_MAJOR_VERSION}-%{RPM_MINOR_VERSION}
 %define docker_build_dir %{_builddir}/%{RPM_NAME}-%{RPM_MAJOR_VERSION}/docker-build
 %define docker_save_dir %{_builddir}/%{RPM_NAME}-%{RPM_MAJOR_VERSION}/docker-save
 %define IMAGE_TAG %{RPM_MAJOR_VERSION}-%{RPM_MINOR_VERSION}
 %define docker_build_dir %{_builddir}/%{RPM_NAME}-%{RPM_MAJOR_VERSION}/docker-build
 %define docker_save_dir %{_builddir}/%{RPM_NAME}-%{RPM_MAJOR_VERSION}/docker-save