path: root/environments/hyperconverged-ceph.yaml
authorJuan Antonio Osorio Robles <jaosorior@redhat.com>2017-03-13 14:30:03 +0200
committerJuan Antonio Osorio Robles <jaosorior@redhat.com>2017-03-13 17:10:13 +0200
commit31bc6eaa88d3af337306349ff6138d01401874c7 (patch)
tree8e44d68a75e78429f3598e986adffc28781ac4d8 /environments/hyperconverged-ceph.yaml
parentb69a73ba85682629460638aa7a8b8f5825c99a1f (diff)
Add certmonger-user profile
This profile will request the certificates for the services on the node. So with this, we will remove the requesting of these certs on the services' profiles themselves. The reasoning for this is that for a containerized environment, the containers won't have credentials to the CA while the baremetal node does. So, with this, we will have this profile that still gets executed in the baremetal nodes, and we can subsequently pass the requested certificates by bind-mounting them on the containers. On the other hand, this approach still works well for the TLS-everywhere case when the services are running on baremetal. Change-Id: Ibf58dfd7d783090e927de6629e487f968f7e05b6 Depends-On: I4d2e62b5c1b893551f9478cf5f69173c334ac81f
1 files changed, 1 insertions, 0 deletions
diff --git a/environments/hyperconverged-ceph.yaml b/environments/hyperconverged-ceph.yaml
index f59b041..8f74ec3 100644
--- a/environments/hyperconverged-ceph.yaml
+++ b/environments/hyperconverged-ceph.yaml
@@ -6,6 +6,7 @@ resource_registry:
- OS::TripleO::Services::CACerts
+ - OS::TripleO::Services::CertmongerUser
- OS::TripleO::Services::CephClient
- OS::TripleO::Services::CephExternal
- OS::TripleO::Services::Timezone