summaryrefslogtreecommitdiffstats
path: root/roles/openshift_service_catalog/tasks/generate_certs.yml
diff options
context:
space:
mode:
authorJeff Peeler <jpeeler@redhat.com>2018-01-10 10:45:59 -0500
committerJeff Peeler <jpeeler@redhat.com>2018-01-10 15:22:31 -0500
commit53bd951747c03e181d0a3fcdb4f93354d7258ed6 (patch)
tree2a4bf82063f9a1c6c118827495be816f94834c66 /roles/openshift_service_catalog/tasks/generate_certs.yml
parentee2d4b8e66a344e8f6ca12cbc9362a80a07555d0 (diff)
downloadopenshift-53bd951747c03e181d0a3fcdb4f93354d7258ed6.tar.gz
openshift-53bd951747c03e181d0a3fcdb4f93354d7258ed6.tar.bz2
openshift-53bd951747c03e181d0a3fcdb4f93354d7258ed6.tar.xz
openshift-53bd951747c03e181d0a3fcdb4f93354d7258ed6.zip
Update deployment and apiserver with new certs
Since new certificates are generated for every run, the apiservice caBundle needs updating in order to have the on disk CA match what is in Kubernetes. Because the secrets are updated, the daemonset needs to do a rolling update for the api server to pick up the new certs. Implemented here is an added annotation to the api server such that the update occurs automatically when the CA is changed.
Diffstat (limited to 'roles/openshift_service_catalog/tasks/generate_certs.yml')
-rw-r--r--roles/openshift_service_catalog/tasks/generate_certs.yml6
1 files changed, 0 insertions, 6 deletions
diff --git a/roles/openshift_service_catalog/tasks/generate_certs.yml b/roles/openshift_service_catalog/tasks/generate_certs.yml
index e478023f8..72110b18c 100644
--- a/roles/openshift_service_catalog/tasks/generate_certs.yml
+++ b/roles/openshift_service_catalog/tasks/generate_certs.yml
@@ -59,11 +59,6 @@
src: "{{ generated_certs_dir }}/ca.crt"
register: apiserver_ca
-- shell: >
- {{ openshift_client_binary }} --config=/etc/origin/master/admin.kubeconfig get apiservices.apiregistration.k8s.io/v1beta1.servicecatalog.k8s.io -n kube-service-catalog || echo "not found"
- register: get_apiservices
- changed_when: no
-
- name: Create api service
oc_obj:
state: present
@@ -86,4 +81,3 @@
caBundle: "{{ apiserver_ca.content }}"
groupPriorityMinimum: 20
versionPriority: 10
- when: "'not found' in get_apiservices.stdout"