Murano does not support SSL with cert for engine<>agent communication

Bug #1568171 reported by Serg Melikyan
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Mirantis OpenStack
Status tracked in 10.0.x
10.0.x
Fix Committed
High
Konstantin
6.1.x
Won't Fix
High
Unassigned
7.0.x
Won't Fix
High
Unassigned
8.0.x
Won't Fix
High
Unassigned
9.x
Fix Released
High
Konstantin

Bug Description

Upstream bug: https://launchpad.net/bugs/1568172

Detailed bug description:
Murano does support specifying certificate for SSL connectivity between murano-engine and murano-agent, but this value (along side with certificate) is not passed to the murano-agent during first VM boot through cloud-init.

Steps to reproduce:
1. Configure SSL for Murano RabbitMQ
2. Configure SSL in Murano:
    vi /etc/murano/murano.conf
    [rabbitmq]
    ...
    ssl=True
    ca_certs=<path-to-cert>
3. Deploy any application

Expected results:
Environment with application deployed successfully

Actual result:
 Environment with application hangs during deployment, murano-agent configuration of VM does not anything related to cert configured

Reproducibility:
  Always

Workaround:
  Update core-library, example for stable/kilo - https://review.openstack.org/301365

Impact:
  Murano does not work on any environment which requires certificates used for SSL connectivity

summary: - Murano does not support TLS with cert for engine<>agent communication
+ Murano does not support SSL with cert for engine<>agent communication
description: updated
tags: added: customer-found
Revision history for this message
Dina Belova (dbelova) wrote :

Setting the same priority/status for the 10.0

Revision history for this message
Serg Melikyan (smelikyan) wrote :
Revision history for this message
Serg Melikyan (smelikyan) wrote :

Waiting for a backport to stable/mitaka and than sync to 9.0 branch

Revision history for this message
Serg Melikyan (smelikyan) wrote :
Revision history for this message
Alex Kholkin (akholkin) wrote :

Verified on #465 ISO
9.0-mos.all

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.