"TASK [set certificate group on host via container] *****************************", │····························································
"fatal: [localhost]: FAILED! => {\"changed\": true, \"cmd\": [\"docker\", \"exec\", \"82cc457cbc14\", \"7b6fd69fe8ac\", \"68128413ad3f\", \"chgrp\", \"haproxy\", \"/var/lib/kolla/config_files/src│····························································
-tls/etc/pki/tls/private/overcloud_endpoint.pem\"], \"delta\": \"0:00:00.096672\", \"end\": \"2018-06-20 10:56:36.090859\", \"msg\": \"non-zero return code\", \"rc\": 126, \"start\": \"2018-06-20 10:56:35.994187│····························································
\", \"stderr\": \"\", \"stderr_lines\": [], \"stdout\": \"rpc error: code = 2 desc = oci runtime error: exec failed: container_linux.go:247: starting container process caused \\\"exec: \\\\\\\"7b6fd69fe8ac\\\\\\│····························································\": executable file not found in $PATH\\\"\", \"stdout_lines\": [\"rpc error: code = 2 desc = oci runtime error: exec failed: container_linux.go:247: starting container process caused \\\"exec: \\\\\\\"7b6fd69fe│····························································8ac\\\\\\\": executable file not found in $PATH\\\"\"]}", │···························································· "\tto retry, use: --limit @/var/lib/heat-config/heat-config-ansible/bdc063af-e89d-4642-9565-285f8bec6356_playbook.retry", │····························································
"",
Our deployment command line was:
openstack overcloud deploy \
--templates /usr/share/openstack-tripleo-heat-templates \
--libvirt-type qemu --control-flavor oooq_control --compute-flavor oooq_compute --ceph-storage-flavor oooq_ceph --block-storage-flavor oooq_blockstorage --swift-storage-flavor oooq_objectstorage --timeout 90 -e /home/stack/cloud-names.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/docker-ha.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/services/neutron-ovn-ha.yaml -e /home/stack/containers-default-parameters.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/network-isolation.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/net-single-nic-with-vlans.yaml -e /home/stack/network-environment.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/low-memory-usage.yaml -e /home/stack/enable-tls.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/tls-endpoints-public-ip.yaml -e /home/stack/inject-trust-anchor.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/disable-telemetry.yaml --validation-warnings-fatal --compute-scale 1 --control-scale 1 --ntp-server pool.ntp.org -e /usr/share/openstack-tripleo-heat-templates/ci/environments/ovb-ha.yaml \
-e /usr/share/openstack-tripleo-heat-templates/environments/docker-ha.yaml \
-e /usr/share/openstack-tripleo-heat-templates/environments/services/neutron-ovn-ha.yaml \
-e /home/stack/ovn-extras.yaml
${DEPLOY_ENV_YAML:+-e $DEPLOY_ENV_YAML} "$@" && status_code=0 || status_code=$?
And the contents of enable-tls.yml
"parameter_defaults":
"GnocchiIncomingStorageDriver": ""
"HorizonSecureCookies": !!bool |-
true
"SSLCertificate": |
-----BEGIN CERTIFICATE-----
MIIDTzCCAjegAwIBAgIBATANBgkqhkiG9w0BAQsFADBhMQswCQYDVQQGEwJVUzEL
MAkGA1UECAwCTkMxEDAOBgNVBAcMB1JhbGVpZ2gxEDAOBgNVBAoMB1JlZCBIYXQx
DTALBgNVBAsMBE9PT1ExEjAQBgNVBAMMCW92ZXJjbG91ZDAeFw0xODA2MDcxOTIy
NDlaFw0xOTA2MDcxOTIyNDlaMGAxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJOQzEQ
MA4GA1UEBwwHUmFsZWlnaDEQMA4GA1UECgwHUmVkIEhhdDENMAsGA1UECwwET09P
UTERMA8GA1UEAwwIMTAuMC4wLjUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
AoIBAQDfXN2nH62nGm8ozAgNmTlU9gHUh404IwrMUtyQLMz/wNExJVRyi58dnBGE
4RNSeLvaJ/6Ho4qqeeCkTkgOyCpDgGZaDWxFN97aPEjYbCywfquuZxcRS6Awud6j
Oo386z7OFJNrxi3QrEB5Jy8/KfS11s/lqxQx3h7yIiDa4MJ5vR9OeoYyrnpRoR6j
1pZnemlBM6If+GcrHi5Pqs7oGIgrA5aTEipwIxzBDQqsk4gsCJXnD0S98tnJ8Mvn
aE/EdYPkccA9aE6KLbKfpzDMYscVN4XHOD1xEB4tShvG+pxUnARPO6n3tDD9n4+N
pmIVaVPJKrAbwQ8ZnEHVtafxjh8XAgMBAAGjEzARMA8GA1UdEQQIMAaHBAoAAAUw
DQYJKoZIhvcNAQELBQADggEBAMR200jD3Mm6KafZKZxJ/ubYA2W/E4WkJK8pleeM
sO9jJYP/mGqnYcSHR0/yttJw3iLTteDiV6aLIIfJCn5CA0q9nOPJBi9w5S665PMZ
Nu2oG3e9uaEDtDRpFbxMQAYBsvNlCUSECxcR0KmZtmkk9kvYC67P1x8HEuEn1dvH
71rpPc5HUJL/wz+rp7ax1jiiRxule9BCqrhGtF0PeLhbk1xIXto10nu3oIgATQHu
qzfEqxYokRRtgKMhn1b4um+lhm9HNUbSQqzRbvk16VS7WzKT9ivr1A1xAgNrO05I
t1r4Gi2Z1lwsXcqPBSs864cBo+ygtdSAI9hvtfAkHLyT16w=
-----END CERTIFICATE-----
"SSLIntermediateCertificate": ""
"SSLKey": |
-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEA31zdpx+tpxpvKMwIDZk5VPYB1IeNOCMKzFLckCzM/8DRMSVU
coufHZwRhOETUni72if+h6OKqnngpE5IDsgqQ4BmWg1sRTfe2jxI2GwssH6rrmcX
EUugMLneozqN/Os+zhSTa8Yt0KxAeScvPyn0tdbP5asUMd4e8iIg2uDCeb0fTnqG
Mq56UaEeo9aWZ3ppQTOiH/hnKx4uT6rO6BiIKwOWkxIqcCMcwQ0KrJOILAiV5w9E
vfLZyfDL52hPxHWD5HHAPWhOii2yn6cwzGLHFTeFxzg9cRAeLUobxvqcVJwETzup
97Qw/Z+PjaZiFWlTySqwG8EPGZxB1bWn8Y4fFwIDAQABAoIBAQC1XtMdQbvgVLau
if6ADEthkeEqkmc5jjrWbvJqn/ZWNlunbIiF+pnZkUEohRsLfL4NByzHNyUCCLVA
tdANMLwg08JInV2tVxC+ZPVBx5UCO9lsZIl2odIRvtvp70IcfWkiLdMHUIUjTLuN
pSPYRllOzn9CHwjm9VZrhwrmsFs6PbKkLzbN7XRU86DPmfU53T+KHipJFt9XuRLL
p/3ofF0oOuw072BJg7MGB1l8UUsfVd2M/OwFwQMoTQUqRtx6kxRvRw99BFr9jsrn
tof56lPhojPu3hRebOmnnn+Hqu5rx+wA5Iw/LYpLAB8f5PyQZDr9L6VlolK5YFu8
2Sioz3kBAoGBAPxswIcosj9egB1noykAuCH7Fc1Ipl3XmSjAkBSKWgNraXDIqDTb
MOjuu+E7P5O/7ijQngMB6d2ToZ0EgD61l6gcWBAesAlNiWNfDRHHP0QkwvH2tch0
jdkbzlIUpbrbdCN+MJKI8kdbAWlxQi5qlrjFWD0kjzkk9g9Q9rpUh1JDAoGBAOKG
vWgxX4KFBkTMd3HsmL8oHAo5EOE7Y0IwJjo1v2o/t5sEAhpA4Fy48bjlWImCRAEp
thnZ/Y0GDHaCe6lL58rWSMyUO8XENvjwPTh+qYaThi01j4a0xGyvihHdOumtO8aa
xvzIiJoVtrr4MjBU68v16prjJT/i2r4ngyxpL+SdAoGBAOTGl9Onsa03M7vywvCV
g0zg6MiOEKI6lchWhf7nyV8SCZU7dx+4jOKABG3EqgF50RrSwHMPV+sHM1FA1A6B
vHqTfcjWV0uHJ36Vlh3HzHIxMzHjHKwZ3rmntt2zcuUgomjMpK8aSSMcuvHawVWa
KxI5YZjAusHa2tvU0Fjd5WtLAoGBAJ8dadnQJHh3nAmjXZtGR5yuPdPodbTflD8f
txpYOpYVH5DhZeCvBWnb9t6bKm+ccswmUmUiO/lc8FAmI1qtmKlfj080KDAoPTzq
8vXF8qo24Z7L6n8CZp65RtB5hzIwnrZIbdGNwnYJHouCXy6X1/EyUZJuTvHrFR9Q
fdEqKZv5AoGAO9CrNbTUA6Tgle7syWIbQUW5VI45R4dctypXYPbAgs6zCU+b5GiS
+3XRRjE4sbWyDIHPeEg1iG3Ji9vZlZyaKSOzNnbAKxMA4RTwN8ei93xwRpL/QcRR
swjNtDn39L4TOHQwyLnMqx2ug/dELumls2DZZJeerxt8fhFbAktBazI=
-----END RSA PRIVATE KEY-----
"resource_registry":
"OS::TripleO::NodeTLSData": |-
/usr/share/openstack-tripleo-heat-templates//puppet/extraconfig/tls/tls-cert-inject.yaml
This is an automated action. Bug status has been set to 'Incomplete' and target milestone has been removed due to inactivity. If you disagree please re-set these values and reach out to us on freenode #tripleo