Fixes to virtual-mcp11-ovs-ironic-ssl model
This patch contains small fixes around ssl setup to
virtual-mcp11-ovs-ironic-ssl model.
Change-Id: Ieb02c7606abe67c7a4b8476e278979caf57e9e81
diff --git a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/baremetal.yml b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/baremetal.yml
index 00855f7..27286fc 100644
--- a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/baremetal.yml
+++ b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/baremetal.yml
@@ -108,6 +108,8 @@
- float-to-ex
ironic:
api:
+ identity:
+ protocol: https
message_queue:
port: ${_param:rabbitmq_port}
ssl:
@@ -116,6 +118,8 @@
ssl:
enabled: ${_param:galera_ssl_enabled}
conductor:
+ identity:
+ protocol: https
message_queue:
port: ${_param:rabbitmq_port}
ssl:
diff --git a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/control.yml b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/control.yml
index 382efa6..0781ed9 100644
--- a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/control.yml
+++ b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/control.yml
@@ -180,6 +180,7 @@
protocol: https
ironic:
api:
+ public_endpoint: https://${_param:cluster_vip_address}:6385
message_queue:
port: ${_param:rabbitmq_port}
ssl:
diff --git a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/init.yml b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/init.yml
index 3de8612..3bfd733 100644
--- a/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/init.yml
+++ b/classes/cluster/virtual-mcp11-ovs-ironic-ssl/openstack/init.yml
@@ -5,7 +5,6 @@
mcp_repo_version: 1.1
openstack_region: RegionOne
admin_email: root@localhost
- cluster_public_protocol: http
cluster_public_host: 172.16.10.254
neutron_public_protocol: http
neutron_control_dvr: False
@@ -95,9 +94,9 @@
mongodb_admin_password: cloudlab
mongodb_shared_key: eoTh1AwahlahqueingeejooLughah4tei9feing0eeVaephooDi2li1TaeV1ooth
linux_system_repo: 'deb [arch=amd64] http://mirror.fuel-infra.org/mcp-repos/ocata/xenial ocata main'
- galera_ssl_enabled: true
- rabbitmq_ssl_enabled: true
- rabbitmq_port: 5671 # for non-ssl use 5672
+ galera_ssl_enabled: false
+ rabbitmq_ssl_enabled: false
+ rabbitmq_port: 5672 # for non-ssl use 5672
cluster_public_protocol: https
cluster_internal_protocol: https
keystone_service_protocol: ${_param:cluster_internal_protocol}