Skip to content

Commit

Permalink
Fix CA mount (#1303)
Browse files Browse the repository at this point in the history
Signed-off-by: Mohammed Naser <[email protected]>
  • Loading branch information
mnaser authored Jun 5, 2024
1 parent f90fc52 commit 0824e92
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 6 deletions.
2 changes: 1 addition & 1 deletion roles/defaults/defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,4 +25,4 @@ atmosphere_network_backend: openvswitch
atmosphere_image_overrides: {}

defaults_ca_certificates_path: >-
{{ '/etc/ssl/certs/ca-certificates.crt' if ansible_facts['os_family'] in ['Debian'] else '/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt' }}"
{{ '/etc/ssl/certs/ca-certificates.crt' if ansible_facts['os_family'] in ['Debian'] else '/etc/pki/ca-trust/extracted/openssl/ca-bundle.trust.crt' }}
4 changes: 2 additions & 2 deletions roles/keystone/vars/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,12 +22,12 @@ _keystone_helm_values:
mounts:
keystone_api:
keystone_api:
volumeMounts: "{{ keystone_domains | vexxhost.atmosphere.keystone_domains_to_mounts + [{'name': 'etc-ssl-certs', 'mountPath': '/etc/ssl/certs', 'readOnly': true}] }}"
volumeMounts: "{{ keystone_domains | vexxhost.atmosphere.keystone_domains_to_mounts + [{'name': 'ca-certificates', 'mountPath': '/etc/ssl/certs/ca-certificates.crt', 'readOnly': true}] }}"
volumes:
- name: keystone-openid-metadata
configMap:
name: keystone-openid-metadata
- name: etc-ssl-certs
- name: ca-certificates
hostPath:
path: "{{ defaults_ca_certificates_path }}"
conf:
Expand Down
6 changes: 3 additions & 3 deletions roles/magnum/vars/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,11 +80,11 @@ _magnum_helm_values:
magnum_conductor:
magnum_conductor:
volumeMounts:
- name: etc-ssl-certs
mountPath: /etc/ssl/certs
- name: ca-certificates
mountPath: /etc/ssl/certs/ca-certificates.crt
readOnly: true
volumes:
- name: etc-ssl-certs
- name: ca-certificates
hostPath:
path: "{{ defaults_ca_certificates_path }}"
manifests:
Expand Down

0 comments on commit 0824e92

Please sign in to comment.