diff options
author | Steven Hardy <shardy@redhat.com> | 2015-12-09 18:23:08 +0000 |
---|---|---|
committer | Steven Hardy <shardy@redhat.com> | 2015-12-09 18:26:03 +0000 |
commit | 293f19b2a41386e1eea47a9e6add24b006c69c42 (patch) | |
tree | b51c3a2dfd32638d97585c7ca5ac4021dafa6f21 /puppet/cinder-storage.yaml | |
parent | 99bd9970d6bedee8228a6c8ff3d6f45aa1380e22 (diff) |
Remove unsafe "unset" defaults
All of our sensitive parameters are defaulted to easily predictable
values, which is very bad from a security perspective because we don't
force clients to make sane choices thus risk deploying with the
predictable default values. tripleoclient supports generating random
values for all of these, so remove the defaults, for non-tripleoclient
usage we can create a developer-only environment with defaults.
Related-Bug: #1516027
Change-Id: Ia0cf3b7e2de1aa42cf179cba195fb7770a1fc21c
Depends-On: Ifb34b43fdedc55ad220df358c3ccc31e3c2e7c14
Diffstat (limited to 'puppet/cinder-storage.yaml')
-rw-r--r-- | puppet/cinder-storage.yaml | 2 |
1 files changed, 0 insertions, 2 deletions
diff --git a/puppet/cinder-storage.yaml b/puppet/cinder-storage.yaml index 82c0e814..3e232ba4 100644 --- a/puppet/cinder-storage.yaml +++ b/puppet/cinder-storage.yaml @@ -17,7 +17,6 @@ parameters: description: The size of the loopback file used by the cinder LVM driver. type: number CinderPassword: - default: unset description: The password for the cinder service and db account, used by cinder-api. type: string hidden: true @@ -70,7 +69,6 @@ parameters: description: The user name for SNMPd with readonly rights running on all Overcloud nodes type: string SnmpdReadonlyUserPassword: - default: unset description: The user password for SNMPd with readonly rights running on all Overcloud nodes type: string hidden: true |