summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAndrew Butcher <abutcher@redhat.com>2016-07-19 15:36:48 -0400
committerAndrew Butcher <abutcher@redhat.com>2016-07-19 18:46:59 -0400
commit6b0e66f285ffa9ed633db4a4eed1974d90128b64 (patch)
tree37ddf060f44d4b9f40f885c8c3d2da5a5b518c64
parent3b9c6afe1684c0c9be6dd1c3a12c493c85c38751 (diff)
downloadopenshift-6b0e66f285ffa9ed633db4a4eed1974d90128b64.tar.gz
openshift-6b0e66f285ffa9ed633db4a4eed1974d90128b64.tar.bz2
openshift-6b0e66f285ffa9ed633db4a4eed1974d90128b64.tar.xz
openshift-6b0e66f285ffa9ed633db4a4eed1974d90128b64.zip
Secure router only when openshift.hosted.router.certificate.contents exists.
-rw-r--r--roles/openshift_hosted/tasks/router/router.yml4
1 files changed, 2 insertions, 2 deletions
diff --git a/roles/openshift_hosted/tasks/router/router.yml b/roles/openshift_hosted/tasks/router/router.yml
index 95f0617dc..dfea8ca4b 100644
--- a/roles/openshift_hosted/tasks/router/router.yml
+++ b/roles/openshift_hosted/tasks/router/router.yml
@@ -32,7 +32,7 @@
content: "{{ openshift.hosted.router.certificate.contents }}"
dest: "{{ openshift_master_config_dir }}/openshift-router.pem"
mode: 0600
- when: openshift.hosted.router.certificate | default(none) is not none
+ when: "'certificate' in openshift.hosted.router and 'contents' in openshift.hosted.router.certificate"
- name: Retrieve list of openshift nodes matching router selector
command: >
@@ -53,7 +53,7 @@
{% if replicas > 1 -%}
--replicas={{ replicas }}
{% endif -%}
- {% if openshift.hosted.router.certificate | default(none) is not none -%}
+ {% if 'certificate' in openshift.hosted.router and 'contents' in openshift.hosted.router.certificate -%}
--default-cert={{ openshift_master_config_dir }}/openshift-router.pem
{% endif -%}
--namespace={{ openshift.hosted.router.namespace | default('default') }}