Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 0 additions & 42 deletions playbooks/byo/openshift-cluster/redeploy-certificates.yml

This file was deleted.

4 changes: 0 additions & 4 deletions playbooks/byo/openshift-cluster/redeploy-etcd-ca.yml

This file was deleted.

18 changes: 0 additions & 18 deletions playbooks/byo/openshift-cluster/redeploy-etcd-certificates.yml

This file was deleted.

10 changes: 0 additions & 10 deletions playbooks/byo/openshift-cluster/redeploy-master-certificates.yml

This file was deleted.

10 changes: 0 additions & 10 deletions playbooks/byo/openshift-cluster/redeploy-node-certificates.yml

This file was deleted.

4 changes: 0 additions & 4 deletions playbooks/byo/openshift-cluster/redeploy-openshift-ca.yml

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
name: etcd
tasks_from: remove_ca_certificates

- include: ../../../openshift-etcd/private/ca.yml
- include: ca.yml

- name: Create temp directory for syncing certs
hosts: localhost
Expand All @@ -44,7 +44,7 @@
etcd_sync_cert_dir: "{{ hostvars['localhost'].g_etcd_mktemp.stdout }}"
etcd_ca_host: "{{ groups.oo_etcd_to_config.0 }}"

- include: ../../../openshift-etcd/private/restart.yml
- include: restart.yml
# Do not restart etcd when etcd certificates were previously expired.
when: ('expired' not in (hostvars
| oo_select_keys(groups['etcd'])
Expand Down Expand Up @@ -82,7 +82,7 @@
state: absent
changed_when: false

- include: ../../../openshift-master/private/restart.yml
- include: ../../openshift-master/private/restart.yml
# Do not restart masters when master or etcd certificates were previously expired.
when:
# masters
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
- name: Check cert expirys
hosts: "{{ g_check_expiry_hosts }}"
hosts: oo_etcd_to_config
vars:
openshift_certificate_expiry_show_all: yes
roles:
Expand All @@ -10,3 +10,9 @@
# this playbook. Service restarts will be skipped if any
# certificates were previously expired.
- role: openshift_certificate_expiry

- include: certificates-backup.yml

- include: certificates.yml
vars:
etcd_certificates_redeploy: true
4 changes: 4 additions & 0 deletions playbooks/openshift-etcd/redeploy-ca.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
- include: ../init/main.yml

- include: private/redeploy-ca.yml
10 changes: 10 additions & 0 deletions playbooks/openshift-etcd/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
- include: ../init/main.yml

- include: private/redeploy-certificates.yml

- include: private/restart.yml
vars:
g_etcd_certificates_expired: "{{ ('expired' in (hostvars | oo_select_keys(groups['etcd']) | oo_collect('check_results.check_results.etcd') | oo_collect('health'))) | bool }}"

- include: ../openshift-master/private/restart.yml
4 changes: 4 additions & 0 deletions playbooks/openshift-hosted/redeploy-registry-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
- include: ../init/main.yml

- include: private/redeploy-registry-certificates.yml
4 changes: 4 additions & 0 deletions playbooks/openshift-hosted/redeploy-router-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
- include: ../init/main.yml

- include: private/redeploy-router-certificates.yml
6 changes: 6 additions & 0 deletions playbooks/openshift-master/private/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
- include: certificates-backup.yml

- include: certificates.yml
vars:
openshift_certificates_redeploy: true
Original file line number Diff line number Diff line change
Expand Up @@ -207,7 +207,7 @@
group: "{{ 'root' if item == 'root' else _ansible_ssh_user_gid.stdout }}"
with_items: "{{ client_users }}"

- include: ../../../openshift-master/private/restart.yml
- include: restart.yml
# Do not restart masters when master or etcd certificates were previously expired.
when:
# masters
Expand Down Expand Up @@ -272,7 +272,7 @@
state: absent
changed_when: false

- include: ../../../openshift-node/private/restart.yml
- include: ../../openshift-node/private/restart.yml
# Do not restart nodes when node, master or etcd certificates were previously expired.
when:
# nodes
Expand Down
6 changes: 6 additions & 0 deletions playbooks/openshift-master/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
- include: ../init/main.yml

- include: private/redeploy-certificates.yml

- include: private/restart.yml
4 changes: 4 additions & 0 deletions playbooks/openshift-master/redeploy-openshift-ca.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
- include: ../init/main.yml

- include: private/redeploy-openshift-ca.yml
6 changes: 6 additions & 0 deletions playbooks/openshift-node/private/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
- include: certificates-backup.yml

- include: certificates.yml
vars:
openshift_certificates_redeploy: true
6 changes: 6 additions & 0 deletions playbooks/openshift-node/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
- include: ../init/main.yml

- include: private/redeploy-certificates.yml

- include: private/restart.yml
26 changes: 26 additions & 0 deletions playbooks/redeploy-certificates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
- include: init/main.yml

- include: openshift-etcd/private/redeploy-certificates.yml

- include: openshift-master/private/redeploy-certificates.yml

- include: openshift-node/private/redeploy-certificates.yml

- include: openshift-etcd/private/restart.yml
vars:
g_etcd_certificates_expired: "{{ ('expired' in (hostvars | oo_select_keys(groups['etcd']) | oo_collect('check_results.check_results.etcd') | oo_collect('health'))) | bool }}"

- include: openshift-master/private/restart.yml

- include: openshift-node/private/restart.yml

- include: openshift-hosted/private/redeploy-router-certificates.yml
when: openshift_hosted_manage_router | default(true) | bool

- include: openshift-hosted/private/redeploy-registry-certificates.yml
when: openshift_hosted_manage_registry | default(true) | bool

- include: openshift-master/private/revert-client-ca.yml

- include: openshift-master/private/restart.yml