internal TLS deployment failed when using containerized mongodb

Bug #1709553 reported by Damien Ciabrini
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
Fix Released
High
Juan Antonio Osorio Robles

Bug Description

When internal TLS is in use, a certificate for mongodb is generated during overcloud deployment, based on the contents of the metadata_settings from the yaml service file [1].

However the containerized version of the mongodb service omits the metadata_settings definition, which confuses certmonger and make the generation of certificates fail. Consequently the deployed overcloud is non functional.

[1] https://review.openstack.org/#/c/461780/

Tags: containers
Changed in tripleo:
importance: Undecided → Critical
status: New → Triaged
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-heat-templates (master)

Fix proposed to branch: master
Review: https://review.openstack.org/492014

Changed in tripleo:
assignee: nobody → Damien Ciabrini (dciabrin)
status: Triaged → In Progress
Changed in tripleo:
milestone: none → pike-rc1
Changed in tripleo:
importance: Critical → High
Changed in tripleo:
assignee: Damien Ciabrini (dciabrin) → Juan Antonio Osorio Robles (juan-osorio-robles)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tripleo-heat-templates (master)

Reviewed: https://review.openstack.org/492014
Committed: https://git.openstack.org/cgit/openstack/tripleo-heat-templates/commit/?id=630ce41fe329c351c5aa80f579c9985c5e5508fb
Submitter: Jenkins
Branch: master

commit 630ce41fe329c351c5aa80f579c9985c5e5508fb
Author: Damien Ciabrini <email address hidden>
Date: Wed Aug 9 07:25:42 2017 +0000

    Fix metadata_settings in containerized mongodb

    The containerized version of the mongodb service omits the
    metadata_settings definition [1], which confuses certmonger when
    internal TLS is enabled and make the generation of certificates fail.

    Use the right setting from the non-containerized profile.

    [1] https://review.openstack.org/#/c/461780/

    Change-Id: I50a9a3a822ba5ef5d2657a12c359b51b7a3a42f2
    Closes-Bug: #1709553

Changed in tripleo:
status: In Progress → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix included in openstack/tripleo-heat-templates 7.0.0.0rc1

This issue was fixed in the openstack/tripleo-heat-templates 7.0.0.0rc1 release candidate.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.