Encrypt passwords.yaml file with ansible vault and decrypt while deploying

Bug #1554018 reported by Prithiv
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
kolla
Invalid
Medium
Prithiv

Bug Description

Passwords.yaml file is visible to all. It should be encrypted using ansible-vault with a password and decrypt it when running kolla-ansible deploy with vault password

Prithiv (prithiv)
Changed in kolla:
assignee: nobody → Prithiv (prithiv)
Revision history for this message
Steven Dake (sdake) wrote :

Is ansible-vault freely available?

Changed in kolla:
status: New → Triaged
importance: Undecided → Wishlist
milestone: none → newton-1
Revision history for this message
Prithiv (prithiv) wrote :

@ sdake yes it is just another command in ansible.

http://docs.ansible.com/ansible/playbooks_vault.html

Revision history for this message
Prithiv (prithiv) wrote :

kolla-ansible deploy runs ansible-playbook in the backend. Instead of that, we just have to run ansible-vault --decrypt. It would ask for the password. Once the password is entered, it will resume the normal deploy operation.

Revision history for this message
Prithiv (prithiv) wrote :

sdake, any update on this ?

Prithiv (prithiv)
Changed in kolla:
importance: Wishlist → Medium
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to kolla (master)

Fix proposed to branch: master
Review: https://review.openstack.org/314945

Prithiv (prithiv)
Changed in kolla:
status: In Progress → Invalid
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on kolla (master)

Change abandoned by Mauricio Lima (<email address hidden>) on branch: master
Review: https://review.openstack.org/314945
Reason: no activity in 4 months

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.