Skip to content

Commit 5030ef4

Browse files
committed
PMM-14118 Use a pre-generated dhparam.pem file
1 parent 2d54f20 commit 5030ef4

File tree

2 files changed

+15
-7
lines changed

2 files changed

+15
-7
lines changed
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
-----BEGIN DH PARAMETERS-----
2+
MIICDAKCAgEAq+0HHfksNBJ9CslMoQ5n0VuQSikNJdT/ryr6IjKsXxZH9t7+WXEQ
3+
GYmvRHP52f8t0GBTuJxkPX4OuWFhMZCSac0QtYxBiT1BnHScUptZaScR4n4Nia0d
4+
FK7ejd1a8LlMXg+Xf1iZLVlDB+xgJw6oFEP6zmAfQy6z0iKiFEYW6WoSGHHzwNQX
5+
FCY4PMlvq0MuBH87d1pGbsKxkEtpAreCaSRiLSI+me7y4S1FkBNrKaoIzBgyZFCe
6+
zCcA0o35DWMucbVHXbzXE4fdZhKuorQoRMhkWZ6kHn0tmhhUILG5j7R/M5dz/cYt
7+
sBImy4SmNhmx3G+u+lAxfELhWf1bVJ22c3EOGmzl0eUSRhWXIxiLV6tqbHLTAvFF
8+
Ny14H7ewVOYrPVTm/1uw1uC4EesNR7nAW81H3vscIKCt4R4zSPxaayN+Du8OKbpn
9+
tE2iXaeOcRwTRs8NbLTJA/9CwOd7XcYY+YGBzgJvC6gzRvwt8wLf2M5Njiv9MFGK
10+
+4bGlk6WHx2wKr3St0ahv4ga4N2nVwMyZrNVFJ5Ai7g5SOMl7pYB2wEJ3FAtelDe
11+
JGjiDNn7qres9pnMfnMFfildZ5vwulcYGHuz0+uDcLq1v4PCvoA8huzfwRKcRJkK
12+
feZsurABRZZCIwLxLgvULfmzVWCj/j271OfEaUCLORR5ut+BMdT/2V8CAQICAgFF
13+
-----END DH PARAMETERS-----

build/ansible/roles/clickhouse/tasks/main.yml

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -19,12 +19,6 @@
1919
enablerepo: clickhouse
2020
ignore_errors: "{{ ansible_check_mode }}" # We don't have clickhouse repo when we run ansible with --check
2121

22-
- name: Generate DH params
23-
command: openssl dhparam -out /etc/clickhouse-server/dhparam.pem 4096
24-
args:
25-
creates: /etc/clickhouse-server/dhparam.pem
26-
no_log: true
27-
2822
- name: Generate SSL certificates
2923
command: openssl req -new -newkey rsa:2048 -days 1095 -nodes -x509 -subj "/CN=localhost" -keyout /etc/clickhouse-server/server.key -out /etc/clickhouse-server/server.crt
3024
args:
@@ -46,7 +40,7 @@
4640
- /var/log/clickhouse-server
4741
- /run/clickhouse-server
4842

49-
- name: Copy customized clickhouse config files
43+
- name: Copy customized clickhouse config files and dhparam.pem
5044
copy:
5145
src: "{{ item }}"
5246
dest: "/etc/clickhouse-server/{{ item }}"
@@ -56,6 +50,7 @@
5650
loop:
5751
- config.xml
5852
- users.xml
53+
- dhparam.pem
5954

6055
# We need to remove capabilities because we run PMM in an unprivileged container
6156
- name: Remove cap_ipc_lock from clickhouse binary

0 commit comments

Comments
 (0)