diff --git a/roles/kubernetes-apps/external_cloud_controller/openstack/tasks/main.yml b/roles/kubernetes-apps/external_cloud_controller/openstack/tasks/main.yml
index 7934fc1cf0dddaf58e725a7c21e22fea2f8387a9..ac3810c7c7417e942e7da22875282be5b188fe3c 100644
--- a/roles/kubernetes-apps/external_cloud_controller/openstack/tasks/main.yml
+++ b/roles/kubernetes-apps/external_cloud_controller/openstack/tasks/main.yml
@@ -7,7 +7,7 @@
     src: "{{ external_openstack_cacert }}"
   register: external_openstack_cacert_b64
   when:
-    - inventory_hostname == groups['k8s_control_plane'][0]
+    - inventory_hostname == groups['kube_control_plane'][0]
     - external_openstack_cacert is defined
     - external_openstack_cacert | length > 0
   tags: external-openstack
diff --git a/roles/kubernetes-apps/external_cloud_controller/openstack/templates/external-openstack-cloud-config-secret.yml.j2 b/roles/kubernetes-apps/external_cloud_controller/openstack/templates/external-openstack-cloud-config-secret.yml.j2
index 06f82234fbe4374c825db500e2d60eb39266424f..2a6f6a8e3e74cd666c61f52cf0c1a8992e5b1cfc 100644
--- a/roles/kubernetes-apps/external_cloud_controller/openstack/templates/external-openstack-cloud-config-secret.yml.j2
+++ b/roles/kubernetes-apps/external_cloud_controller/openstack/templates/external-openstack-cloud-config-secret.yml.j2
@@ -7,5 +7,7 @@ metadata:
   name: external-openstack-cloud-config
   namespace: kube-system
 data:
-  cloud.conf: {{ external_openstack_cloud_config_secret.content }}
-  ca.cert: {{ external_openstack_cacert_b64.content | default("") }}
+  cloud.conf: {{ external_openstack_cloud_config_secret }}
+{% if external_openstack_cacert_b64.content is defined %}
+  ca.cert: {{ external_openstack_cacert_b64.content }}
+{% endif %}