Switch Jenkins DT on TLS/HTTPS scheme
Change-Id: I82b2d094da87668eb762ad4e5674e4e67561edd4
Related-Prod: PROD-27541 (PROD:27541)
(cherry-picked from commit 1cfead8d9d2c13241a5b62b4dac657b6bb1cd479)
diff --git a/defaults/jenkins.yml b/defaults/jenkins.yml
index d01bf4e..68d843d 100644
--- a/defaults/jenkins.yml
+++ b/defaults/jenkins.yml
@@ -1,6 +1,6 @@
parameters:
_param:
jenkins_master_port: 8081
- jenkins_master_protocol: http
+ jenkins_master_protocol: https
jenkins_pipelines_branch: "master"
jenkins_salt_api_url: "https://${_param:salt_master_host}:${_param:nginx_proxy_salt_api_site_port}"
diff --git a/haproxy/proxy/listen/cicd/jenkins.yml b/haproxy/proxy/listen/cicd/jenkins.yml
index d8c67d0..9f3bf07 100644
--- a/haproxy/proxy/listen/cicd/jenkins.yml
+++ b/haproxy/proxy/listen/cicd/jenkins.yml
@@ -1,3 +1,5 @@
+classes:
+ - system.salt.minion.cert.proxy.drivetrain_ssl
parameters:
_param:
haproxy_jenkins_bind_host: ${_param:haproxy_bind_address}
@@ -5,7 +7,8 @@
haproxy_jenkins_jnlp_bind_host: ${_param:haproxy_jenkins_bind_host}
haproxy_jenkins_jnlp_bind_port: 50000
haproxy_jenkins_ssl:
- enabled: false
+ enabled: true
+ pem_file: /etc/haproxy/ssl/drivetrain.pem
haproxy:
proxy:
listen:
diff --git a/jenkins/client/init.yml b/jenkins/client/init.yml
index 11b5430..aa8cf0d 100644
--- a/jenkins/client/init.yml
+++ b/jenkins/client/init.yml
@@ -18,6 +18,7 @@
master:
host: ${_param:jenkins_master_host}
port: ${_param:jenkins_master_port}
+ proto: https
username: ${_param:jenkins_client_user}
password: ${_param:jenkins_client_password}
lib: