File tree Expand file tree Collapse file tree 3 files changed +7
-4
lines changed
environments/ci-multinode/kolla/config Expand file tree Collapse file tree 3 files changed +7
-4
lines changed Original file line number Diff line number Diff line change @@ -296,6 +296,7 @@ Configure Barbican
296
296
[vault_plugin]
297
297
vault_url = https://{{ kolla_internal_vip_address }}:8200
298
298
use_ssl = True
299
+ ssl_ca_crt_file = {% raw %}{{ openstack_cacert }}{% endraw %}
299
300
approle_role_id = {{ secrets_barbican_approle_role_id }}
300
301
approle_secret_id = {{ secrets_barbican_approle_secret_id }}
301
302
kv_mountpoint = barbican
Original file line number Diff line number Diff line change 82
82
copy :
83
83
content : " {{ barbican_role_id.id }}"
84
84
dest : " {{ stackhpc_barbican_role_id_file_path | default('~/barbican-role-id') }}"
85
- when : stackhpc_write_barbican_role_id_to_file | bool | default(false)
85
+ when : stackhpc_write_barbican_role_id_to_file | default(false) | bool
86
86
87
87
- name : Check if barbican Approle Secret ID is defined
88
- hashivault_approle_role_secret_list :
88
+ hashivault_approle_role_secret_get :
89
89
url : " {{ vault_api_addr }}"
90
90
ca_cert : " {{ vault_ca_cert }}"
91
91
token : " {{ vault_keys.root_token }}"
92
+ secret : " {{ secrets_barbican_approle_secret_id }}"
92
93
name : barbican
93
- register : barbican_approle_secret_list
94
+ register : barbican_approle_secret_get
94
95
95
96
- name : Ensure barbican AppRole Secret ID is defined
96
97
hashivault_approle_role_secret :
99
100
token : " {{ vault_keys.root_token }}"
100
101
secret : " {{ secrets_barbican_approle_secret_id }}"
101
102
name : barbican
102
- when : barbican_approle_secret_list.secrets is match(secrets_barbican_approle_secret_id)
103
+ when : barbican_approle_secret_get.status == "absent"
Original file line number Diff line number Diff line change @@ -7,6 +7,7 @@ enabled_secretstore_plugins=vault_plugin
7
7
[vault_plugin]
8
8
vault_url = https://{{ kolla_internal_vip_address }}:8200
9
9
use_ssl = True
10
+ ssl_ca_crt_file = {% raw %}{{ openstack_cacert }}{% endraw %}
10
11
approle_role_id = {{ secrets_barbican_approle_role_id }}
11
12
approle_secret_id = {{ secrets_barbican_approle_secret_id }}
12
13
kv_mountpoint = barbican
You can’t perform that action at this time.
0 commit comments