diff options
author | Jenkins <jenkins@review.openstack.org> | 2017-03-09 22:56:55 +0000 |
---|---|---|
committer | Gerrit Code Review <review@openstack.org> | 2017-03-09 22:56:55 +0000 |
commit | 78b7a7ed8a6b9af70f300d98f1c7f1c4eb715629 (patch) | |
tree | af7b3f26d932b589a1f742680f1bc644847f33b6 /puppet/services/rabbitmq-internal-tls-certmonger.yaml | |
parent | a8d511a05e2f94af177155546bcc5b74ee0329a0 (diff) | |
parent | 1992282b88beed0df0a25e54b4bd92bbc3b1919f (diff) |
Merge "Pass hieradata for internal TLS for RabbitMQ"
Diffstat (limited to 'puppet/services/rabbitmq-internal-tls-certmonger.yaml')
-rw-r--r-- | puppet/services/rabbitmq-internal-tls-certmonger.yaml | 47 |
1 files changed, 47 insertions, 0 deletions
diff --git a/puppet/services/rabbitmq-internal-tls-certmonger.yaml b/puppet/services/rabbitmq-internal-tls-certmonger.yaml new file mode 100644 index 00000000..39d6b903 --- /dev/null +++ b/puppet/services/rabbitmq-internal-tls-certmonger.yaml @@ -0,0 +1,47 @@ +heat_template_version: ocata + +description: > + RabbitMQ configurations for using TLS via certmonger. + +parameters: + ServiceNetMap: + default: {} + description: Mapping of service_name -> network name. Typically set + via parameter_defaults in the resource registry. This + mapping overrides those in ServiceNetMapDefaults. + type: json + # The following parameters are not needed by the template but are + # required to pass the pep8 tests + DefaultPasswords: + default: {} + type: json + EndpointMap: + default: {} + description: Mapping of service endpoint -> protocol. Typically set + via parameter_defaults in the resource registry. + type: json + +outputs: + role_data: + description: RabbitMQ configurations for using TLS via certmonger. + value: + service_name: rabbitmq_internal_tls_certmonger + config_settings: + generate_service_certificates: true + tripleo::profile::base::rabbitmq::certificate_specs: + service_certificate: '/etc/pki/tls/certs/rabbitmq.crt' + service_key: '/etc/pki/tls/private/rabbitmq.key' + hostname: + str_replace: + template: "%{hiera('fqdn_NETWORK')}" + params: + NETWORK: {get_param: [ServiceNetMap, RabbitmqNetwork]} + principal: + str_replace: + template: "rabbitmq/%{hiera('fqdn_NETWORK')}" + params: + NETWORK: {get_param: [ServiceNetMap, RabbitmqNetwork]} + metadata_settings: + - service: rabbitmq + network: {get_param: [ServiceNetMap, RabbitmqNetwork]} + type: node |