Jim Rigsbee
2019-12-18 1db82af9f3656c76d574c2c713d5cbce2895665f
Fixes for cert renewal on OpenShift API/Router
2 files modified
5 ■■■■■ changed files
ansible/roles/ocp4-workload-enable-lets-encrypt-certificates/files/deploy_certs.sh 2 ●●● patch | view | raw | blame | history
ansible/roles/ocp4-workload-enable-lets-encrypt-certificates/files/deploy_certs.yml 3 ●●●● patch | view | raw | blame | history
ansible/roles/ocp4-workload-enable-lets-encrypt-certificates/files/deploy_certs.sh
@@ -1,4 +1,4 @@
#!/bin/bash
pushd ~/certbot/config/renewal-hooks/deploy
ansible-playbook ./deploy_certs.yml
ansible-playbook ./deploy_certs.yml -e cluster_name="{{cluster_name}}"
popd
ansible/roles/ocp4-workload-enable-lets-encrypt-certificates/files/deploy_certs.yml
@@ -11,6 +11,8 @@
  - _certbot_install_dir: "/home/{{ ansible_user }}/certificates"
  - _certbot_remote_dir: "/home/{{ ansible_user }}"
  - _certbot_dir: "{{ _certbot_remote_dir }}/certbot"
  environment:
    KUBECONFIG: /home/{{ansible_user}}/{{cluster_name}}/auth/kubeconfig
  tasks:
  - name: Determine API server hostname
    shell: "oc whoami --show-server | cut -f 2 -d ':' | cut -f 3 -d '/' | sed 's/-api././'"
@@ -107,4 +109,3 @@
      regexp: "^ +certificate-authority-data:"
      state: absent
    loop: "{{r_config_files.files}}"