Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-65969

Set the tls cacert path to writable mount when the IRONIC_CACERT_FILE is unset

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None
    • 2
    • None
    • None
    • None
    • Rejected
    • Metal Platform 280
    • 1
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      The current default IRONIC_CACERT_FILE=/certs/ca/ironic/tls.crt is a readOnly path in ironic-image, which will fail when we copy the cert file to cacert file to cover for self-signed certs scenario, link - https://github.com/openshift/ironic-image/blob/main/scripts/tls-common.sh#L69-L70.

      So, setting the default under CUSTOM_CONFIG_DIR=/conf, IRONIC_CACERT_FILE=/conf/certs/ca/ironic/tls.crt, should fix the problem.

              hroy@redhat.com Himanshu Roy
              hroy@redhat.com Himanshu Roy
              None
              None
              Jad Haj Yahya Jad Haj Yahya
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: