diff options
| author | Andrew Butcher <abutcher@redhat.com> | 2017-11-06 12:35:13 -0500 | 
|---|---|---|
| committer | Andrew Butcher <abutcher@redhat.com> | 2017-11-06 17:05:16 -0500 | 
| commit | 89fcbb72447ab74b440c15d1e35a1dd10cef1c49 (patch) | |
| tree | 417baa390469950d6fa367057ccf47755c35f38d /roles/openshift_ca/tasks | |
| parent | 5efcf4a2f7e9c2f21c6f9f86dc08f12fd5f56290 (diff) | |
| download | openshift-89fcbb72447ab74b440c15d1e35a1dd10cef1c49.tar.gz openshift-89fcbb72447ab74b440c15d1e35a1dd10cef1c49.tar.bz2 openshift-89fcbb72447ab74b440c15d1e35a1dd10cef1c49.tar.xz openshift-89fcbb72447ab74b440c15d1e35a1dd10cef1c49.zip  | |
Temporarily set master servingInfo.clientCA as client-ca-bundle.crt during rolling CA redeployment.
Diffstat (limited to 'roles/openshift_ca/tasks')
| -rw-r--r-- | roles/openshift_ca/tasks/main.yml | 30 | 
1 files changed, 30 insertions, 0 deletions
diff --git a/roles/openshift_ca/tasks/main.yml b/roles/openshift_ca/tasks/main.yml index fad1ff5de..587526d07 100644 --- a/roles/openshift_ca/tasks/main.yml +++ b/roles/openshift_ca/tasks/main.yml @@ -106,6 +106,36 @@    delegate_to: "{{ openshift_ca_host }}"    run_once: true +# Create client-ca-bundle.crt containing old and new OpenShift CA +# certificates. This bundle will be used when rolling the OpenShift CA +# certificate. +- name: Create client-ca-bundle.crt +  block: +  - command: mktemp -d /tmp/openshift-ansible-XXXXXX +    register: openshift_ca_clientconfig_tmpdir +    delegate_to: "{{ openshift_ca_host }}" +  - copy: +      src: "{{ item }}" +      dest: "{{ openshift_ca_clientconfig_tmpdir.stdout }}/" +      remote_src: true +    with_items: "{{ g_master_legacy_ca_result.files | default([]) | oo_collect('path') }}" +    delegate_to: "{{ openshift_ca_host }}" +    run_once: true +  - copy: +      src: "{{ openshift_ca_config_dir }}/ca.crt" +      dest: "{{ openshift_ca_clientconfig_tmpdir.stdout }}/" +      remote_src: true +    delegate_to: "{{ openshift_ca_host }}" +    run_once: true +  - assemble: +      src: "{{ openshift_ca_clientconfig_tmpdir.stdout }}" +      dest: "{{ openshift_ca_config_dir }}/client-ca-bundle.crt" +      mode: 0644 +      owner: root +      group: root +    delegate_to: "{{ openshift_ca_host }}" +    run_once: true +  - name: Test local loopback context    command: >      {{ hostvars[openshift_ca_host].openshift.common.client_binary }} config view  | 
