summaryrefslogtreecommitdiffstats
path: root/roles/openshift_metrics/tasks/generate_certificates.yaml
blob: 66cfbca0390a3c5b903e0e37dc72759b94a50777 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
---
- name: create certificate output directory
  file:
    path: "{{ openshift_metrics_certs_dir }}"
    state: directory
    mode: 0700
- name: list existing secrets
  command: >
    {{ openshift.common.client_binary }} -n {{ openshift_metrics_project }}
    --config={{ mktemp.stdout }}/admin.kubeconfig
    get secrets -o name
  register: metrics_secrets
  changed_when: false
- name: generate ca certificate chain
  shell: >
    {{ openshift.common.admin_binary }} ca create-signer-cert
    --config={{ mktemp.stdout }}/admin.kubeconfig
    --key='{{ openshift_metrics_certs_dir }}/ca.key'
    --cert='{{ openshift_metrics_certs_dir }}/ca.crt'
    --serial='{{ openshift_metrics_certs_dir }}/ca.serial.txt'
    --name="metrics-signer@$(date +%s)"
  when: not '{{ openshift_metrics_certs_dir }}/ca.key' | exists
- include: generate_heapster_certificates.yaml
- include: generate_hawkular_certificates.yaml