Ceph-rgw fails on tls-e

Bug #1989831 reported by Cristian Le
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tripleo
In Progress
Undecided
Unassigned

Bug Description

There are two issues due to hard-coded heat template values [1].

First, `/etc/ipa/ca.crt` might not be the correct CA one needs, and should be replaced with the parameters in `InternalTLSCAFile`. It might be problematic if the CA contains expired intermediate CAs, but I can't pinpoint the exact cause of deployment failure.

Second, uid should be `167` according to tripleo-ansible [2],[3]. But better yet, this should be exposed as a heat template variable so it can be changed everywhere, including other hard-coded places like [4]

[1] https://opendev.org/openstack/tripleo-heat-templates/src/commit/f1c6c6d3026e931bb494cd53dc95b157c8e2a10c/deployment/cephadm/ceph-rgw.yaml#L199-L201
[2] https://opendev.org/openstack/tripleo-ansible/src/commit/e5a661b55408c1061108d6da2529a83f78ebef3b/tripleo_ansible/roles/tripleo_cephadm/defaults/main.yml#L33
[3] https://opendev.org/openstack/tripleo-ansible/src/commit/948a5f23d866e2d30a5d4c2e723a63d1aae637e6/tripleo_ansible/roles/tripleo_ceph_distribute_keys/defaults/main.yml#L27
[4] https://opendev.org/openstack/tripleo-ansible/src/commit/bae33e72d01822496f42636baffcbe99059a4b91/tripleo_ansible/roles/tripleo_cephadm/tasks/ganesha/distribute_keys.yaml#L22-L23

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tripleo-heat-templates (master)
Changed in tripleo:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on tripleo-heat-templates (master)

Change abandoned by "Ghanshyam <email address hidden>" on branch: master
Review: https://review.opendev.org/c/openstack/tripleo-heat-templates/+/857996
Reason: TrieplO project is retiring now, for details, please see https://review.opendev.org/c/openstack/governance/+/905145 or reach out to OpenStack TC.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.