Add a new label 'cert_manager_api' to kubernetes clusters controlling the
enable/disable of the kubernetes certificate manager api.
The same cluster cert/key pair is used by this api. The heat agent is used
to install the key in the master node(s), as this is required for kubernetes
to later sign new certificate requests.
The master template init order is changed so the heat agent is launched
previous to enabling the services - the controller manager requires the CA key
to be locally available before being launched.
Reviewed: https:/ /review. openstack. org/529818 /git.openstack. org/cgit/ openstack/ magnum/ commit/ ?id=faa9e90402b cf78acdd166198f ff9612fa8be81c
Committed: https:/
Submitter: Zuul
Branch: master
commit faa9e90402bcf78 acdd166198fff96 12fa8be81c
Author: Ricardo Rocha <email address hidden>
Date: Fri Dec 22 11:07:51 2017 +0000
[k8s] allow enabling kubernetes cert manager api
Add a new label 'cert_manager_api' to kubernetes clusters controlling the
enable/disable of the kubernetes certificate manager api.
The same cluster cert/key pair is used by this api. The heat agent is used
to install the key in the master node(s), as this is required for kubernetes
to later sign new certificate requests.
The master template init order is changed so the heat agent is launched
previous to enabling the services - the controller manager requires the CA key
to be locally available before being launched.
Change-Id: Ibf85147316e3a1 94d8a3f92cbb4ae 9ce8e16c98f
Partial-Bug: #1734318