Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[tlse] internal TLS support for octavia #715

Merged

Conversation

Deydra71
Copy link
Contributor

Creates certs for k8s service of the service operator when spec.tls.endpoint.internal.enabled: true

For a service like nova which talks to multiple service internal endpoints, this has to be set for each of them for, like:

customServiceConfig: |
[keystone_authtoken]
insecure = true
[placement]
insecure = true
[neutron]
insecure = true
[glance]
insecure = true
[cinder]
insecure = true
Depends-On: openstack-k8s-operators/lib-common#428 Depends-On: #620
Depends-On: openstack-k8s-operators/octavia-operator#265

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/dd0c3cb22b604b7c97f422df58d55513

openstack-k8s-operators-content-provider FAILURE in 8m 14s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ openstack-operator-tempest-multinode SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider

@@ -104,6 +110,10 @@ func ReconcileOctavia(ctx context.Context, instance *corev1beta1.OpenStackContro
instance.Spec.Octavia.Template.OctaviaAPI.Override.Service = endpointDetails.GetEndpointServiceOverrides()
}

// update TLS settings with cert secret
instance.Spec.Octavia.Template.OctaviaAPI.TLS.API.Public.SecretName = endpointDetails.GetEndptCertSecret(service.EndpointPublic)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

endpointDetails is not defined in this scope

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hope you don't mind - I've pushed a fix (guessing that's should have been in the if block) and updated octavia-operator as the PR has now merged

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cool, thanks! I stashed them and put you as a co-author.

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/bcc43881ec944947b582b35c530c314a

✔️ openstack-k8s-operators-content-provider SUCCESS in 19m 12s
podified-multinode-edpm-deployment-crc RETRY_LIMIT in 4s
cifmw-crc-podified-edpm-baremetal RETRY_LIMIT in 4s
cifmw-data-plane-adoption-osp-17-to-extracted-crc RETRY_LIMIT in 3s
openstack-operator-tempest-multinode RETRY_LIMIT in 3s

@Deydra71 Deydra71 force-pushed the tls-support-octavia branch from 63d2635 to 0ecee7e Compare March 27, 2024 07:44
Creates certs for k8s service of the service operator when spec.tls.endpoint.internal.enabled: true

For a service like nova which talks to multiple service internal endpoints, this has to be set for each of them for, like:

  customServiceConfig: |
    [keystone_authtoken]
    insecure = true
    [placement]
    insecure = true
    [neutron]
    insecure = true
    [glance]
    insecure = true
    [cinder]
    insecure = true

Depends-On: openstack-k8s-operators/lib-common#428
Depends-On: openstack-k8s-operators#620
Depends-On: openstack-k8s-operators/octavia-operator#265
Co-authored-by: [email protected]

Signed-off-by: Veronika Fisarova <[email protected]>
@Deydra71 Deydra71 force-pushed the tls-support-octavia branch from 0ecee7e to 9738341 Compare March 27, 2024 07:47
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/eee5b7f0d126403ca60526180d6f13b6

✔️ openstack-k8s-operators-content-provider SUCCESS in 2h 29m 11s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 12m 41s
cifmw-crc-podified-edpm-baremetal RETRY_LIMIT in 3s
✔️ cifmw-data-plane-adoption-osp-17-to-extracted-crc SUCCESS in 2h 10m 53s
openstack-operator-tempest-multinode RETRY_LIMIT in 3s

@Deydra71
Copy link
Contributor Author

recheck

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/10d9775eca6d4806ad3346c8f34edc6c

✔️ openstack-k8s-operators-content-provider SUCCESS in 2h 36m 56s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 11m 32s
cifmw-crc-podified-edpm-baremetal FAILURE in 19m 48s
cifmw-data-plane-adoption-osp-17-to-extracted-crc FAILURE in 2h 18m 35s
openstack-operator-tempest-multinode FAILURE in 1h 33m 50s

@Deydra71
Copy link
Contributor Author

recheck

Copy link
Contributor

@olliewalsh olliewalsh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Copy link
Contributor

openshift-ci bot commented Mar 27, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Deydra71, olliewalsh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/fe3b2ca064aa4d3f9db1c419acddfbc1

✔️ openstack-k8s-operators-content-provider SUCCESS in 4h 24m 45s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 12m 48s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 29m 01s
✔️ cifmw-data-plane-adoption-osp-17-to-extracted-crc SUCCESS in 2h 22m 20s
openstack-operator-tempest-multinode FAILURE in 1h 33m 12s

@olliewalsh
Copy link
Contributor

recheck

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://review.rdoproject.org/zuul/buildset/607392401d4b4ad6ae3d1c20f5879881

openstack-k8s-operators-content-provider FAILURE in 12m 24s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-data-plane-adoption-osp-17-to-extracted-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ openstack-operator-tempest-multinode SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider

@Deydra71
Copy link
Contributor Author

recheck

@openshift-merge-bot openshift-merge-bot bot merged commit 9af21c8 into openstack-k8s-operators:main Mar 27, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants