Build combined config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
This commit is contained in:
parent
37131d4ef5
commit
c6a33bd8fb
2 changed files with 26 additions and 2 deletions
|
@ -23,9 +23,15 @@
|
||||||
- rabbitmq_cluster
|
- rabbitmq_cluster
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: create node cert directory
|
||||||
|
file: path=/etc/rabbitmq/nodecert/ owner=root group=root mode=0644 state=directory
|
||||||
|
tags:
|
||||||
|
- rabbitmq_cluster
|
||||||
|
- config
|
||||||
|
|
||||||
- name: deploy node certificate
|
- name: deploy node certificate
|
||||||
copy: src="{{private}}/files/rabbitmq/{{env}}/pki/issued/{{inventory_hostname}}.crt"
|
copy: src="{{private}}/files/rabbitmq/{{env}}/pki/issued/{{inventory_hostname}}.crt"
|
||||||
dest=/etc/rabbitmq/node.crt
|
dest=/etc/rabbitmq/nodecert/node.crt
|
||||||
owner=root group=root mode=0644
|
owner=root group=root mode=0644
|
||||||
tags:
|
tags:
|
||||||
- rabbitmq_cluster
|
- rabbitmq_cluster
|
||||||
|
@ -33,12 +39,19 @@
|
||||||
|
|
||||||
- name: deploy node private key
|
- name: deploy node private key
|
||||||
copy: src="{{private}}/files/rabbitmq/{{env}}/pki/private/{{inventory_hostname}}.key"
|
copy: src="{{private}}/files/rabbitmq/{{env}}/pki/private/{{inventory_hostname}}.key"
|
||||||
dest=/etc/rabbitmq/node.key
|
dest=/etc/rabbitmq/nodecert/node.key
|
||||||
owner=rabbitmq group=rabbitmq mode=0600
|
owner=rabbitmq group=rabbitmq mode=0600
|
||||||
tags:
|
tags:
|
||||||
- rabbitmq_cluster
|
- rabbitmq_cluster
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: build combined node key
|
||||||
|
assemble: src=/etc/rabbitmq/nodecert/ dest=/etc/rabbitmq/nodecert.combined.pem
|
||||||
|
owner=rabbitmq group=rabbitmq mode=0600
|
||||||
|
tags:
|
||||||
|
- rabbitmq_cluster
|
||||||
|
- config
|
||||||
|
|
||||||
- name: enable plugins
|
- name: enable plugins
|
||||||
copy: src=enabled_plugins dest=/etc/rabbitmq/enabled_plugins owner=root group=root mode=0644
|
copy: src=enabled_plugins dest=/etc/rabbitmq/enabled_plugins owner=root group=root mode=0644
|
||||||
with_items:
|
with_items:
|
||||||
|
|
|
@ -0,0 +1,11 @@
|
||||||
|
ERL_SSL_PATH="/usr/lib64/erlang/lib/ssl-7.3.3.2/ebin"
|
||||||
|
|
||||||
|
SERVER_ADDITIONAL_ERL_ARGS="-pa $ERL_SSL_PATH \
|
||||||
|
-proto_dist inet_tls \
|
||||||
|
-ssl_dist_opt server_certfile /etc/rabbitmq/node.combined.pem \
|
||||||
|
-ssl_dist_opt server_secure_renegotiate true client_secure_renegotiate true"
|
||||||
|
|
||||||
|
CTL_ERL_ARGS="-pa $ERL_SSL_PATH \
|
||||||
|
-proto_dist inet_tls \
|
||||||
|
-ssl_dist_opt server_certfile /etc/rabbitmq/node.combined.pem \
|
||||||
|
-ssl_dist_opt server_secure_renegotiate true client_secure_renegotiate true"
|
Loading…
Add table
Add a link
Reference in a new issue