blob: cf7b3282a795f421a7da402f25cc2c5c89e43be2 [file] [log] [blame]
Oleksii Grudev6eb64342018-08-10 15:46:07 +03001parameters:
Oleksii Grudev614facd2018-08-20 13:20:29 +03002 _param:
3 fernet_rotation_driver: 'rsync'
4 credential_rotation_driver: 'rsync'
Oleksii Grudev6eb64342018-08-10 15:46:07 +03005 keystone:
6 server:
7 tokens:
8 fernet_sync_nodes_list:
9 sync_node01:
Oleksii Grudev614facd2018-08-20 13:20:29 +030010 name: ${_param:cluster_node02_hostname}
Oleksii Grudev6eb64342018-08-10 15:46:07 +030011 enabled: True
12 sync_node02:
Oleksii Grudev614facd2018-08-20 13:20:29 +030013 name: ${_param:cluster_node03_hostname}
Oleksii Grudev6eb64342018-08-10 15:46:07 +030014 enabled: True
Oleksii Grudev614facd2018-08-20 13:20:29 +030015 fernet_rotation_driver: ${_param:fernet_rotation_driver}
Oleksii Grudev3b31b4d2018-08-17 11:19:11 +030016 credential:
17 credential_sync_nodes_list:
18 sync_node01:
Oleksii Grudev614facd2018-08-20 13:20:29 +030019 name: ${_param:cluster_node02_hostname}
Oleksii Grudev3b31b4d2018-08-17 11:19:11 +030020 enabled: True
21 sync_node02:
Oleksii Grudev614facd2018-08-20 13:20:29 +030022 name: ${_param:cluster_node03_hostname}
Oleksii Grudev3b31b4d2018-08-17 11:19:11 +030023 enabled: True
Oleksii Grudev614facd2018-08-20 13:20:29 +030024 credential_rotation_driver: ${_param:credential_rotation_driver}
Oleksii Grudev6eb64342018-08-10 15:46:07 +030025 linux:
26 system:
Oleksii Grudevedb5fa12018-09-26 15:44:46 +030027 package:
28 rsync:
29 version: latest
Dmitry Teselkin986260f2018-08-30 19:07:25 +030030 cron:
31 user:
32 keystone:
33 enabled: true
Oleksii Grudev6eb64342018-08-10 15:46:07 +030034 job:
35 keystone_fernet_rotate_rsync:
Oleksii Grudev3b31b4d2018-08-17 11:19:11 +030036 command: '/var/lib/keystone/keystone_keys_rotate.sh -r -s -t fernet >> /var/log/keystone/keystone-rotate.log 2>> /var/log/keystone/keystone-rotate.log'
Oleksii Grudev6eb64342018-08-10 15:46:07 +030037 enabled: true
38 user: keystone
Oleksandr Bryndzii1558a8e2019-02-27 14:23:23 +020039 minute: ${_param:keystone_fernet_rotate_rsync_minute}
40 hour: ${_param:keystone_fernet_rotate_rsync_hour}
Oleksii Grudev3b31b4d2018-08-17 11:19:11 +030041 keystone_credential_rotate_rsync:
42 command: '/var/lib/keystone/keystone_keys_rotate.sh -r -s -t credential >> /var/log/keystone/keystone-rotate.log 2>> /var/log/keystone/keystone-rotate.log'
43 enabled: true
44 user: keystone
45 hour: 0
46 minute: 0