Services which require DB fail to initialize when deployed with internal TLS

Bug #1710127 reported by Damien Ciabrini on 2017-08-11
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Juan Antonio Osorio Robles

Bug Description

When internal TLS is in use, mysql/galera only accepts incoming TCP connection when they use SSL.

With containerized deployments, various services (e.g. nova, neutron, heat) run initial set up steps via some ephemeral containers. If those containers don't use kolla_start, the necessary mysql configuration will not be copied in /etc/my.cnf.d, and the connection to the DB won't use SSL. This makes the overcloud deployment fail.

Fix proposed to branch: master

Changed in tripleo:
assignee: nobody → Damien Ciabrini (dciabrin)
status: Triaged → In Progress
Changed in tripleo:
milestone: none → pike-rc1
Changed in tripleo:
assignee: Damien Ciabrini (dciabrin) → Juan Antonio Osorio Robles (juan-osorio-robles)

Submitter: Jenkins
Branch: master

commit 5144634d9bc3afd79ff934b9e913f6b9689e374b
Author: Damien Ciabrini <email address hidden>
Date: Fri Aug 11 11:24:12 2017 +0000

    Bind mount tripleo.cnf in transient bootstrap containers

    Various containerized services (e.g. nova, neutron, heat) run initial set up
    steps with some ephemeral containers that don't use kolla_start. The
    tripleo.cnf file is not copied in /etc/my.cnf.d and this can break some
    deployments (e.g. when using internal TLS, service lack SSL settings).

    Fix the configuration of transient containers by bind mounting of the
    tripleo.cnf file when kolla_start is not used.

    Change-Id: I5246f9d52fcf8c8af81de7a0dd8281169c971577
    Closes-Bug: #1710127
    Co-Authored-By: Juan Antonio Osorio Robles <email address hidden>

Changed in tripleo:
status: In Progress → Fix Released

This issue was fixed in the openstack/tripleo-heat-templates release candidate.

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers