Skip to content
  • Maxim Krasilnikov's avatar
    Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) · 6eb22c5d
    Maxim Krasilnikov authored
    * Added update CA trust step for etcd and kube/secrets roles
    
    * Added load_balancer_domain_name to certificate alt names if defined. Reset CA's in RedHat os.
    
    * Rename kube-cluster-ca.crt to vault-ca.crt, we need separated CA`s for vault, etcd and kube.
    
    * Vault role refactoring, remove optional cert vault auth because not not used and worked. Create separate CA`s fro vault and etcd.
    
    * Fixed different certificates set for vault cert_managment
    
    * Update doc/vault.md
    
    * Fixed condition create vault CA, wrong group
    
    * Fixed missing etcd_cert_path mount for rkt deployment type. Distribute vault roles for all vault hosts
    
    * Removed wrong when condition in create etcd role vault tasks.
    6eb22c5d
Loading