From b848cef629dfbf83b638281e57361a383aa0a1f2 Mon Sep 17 00:00:00 2001 From: Juan Antonio Osorio Robles Date: Tue, 19 Mar 2019 10:15:25 +0200 Subject: [PATCH] Only bind-mount internal TLS haproxy dirs if enabled We were bind-mounting those directories when public TLS was enabled... it needed to be in the internal TLS conditional. Change-Id: I7487c0f3b495dce2f5ce3028e8516cc3c215f896 Closes-Bug: #1820577 --- deployment/haproxy/haproxy-pacemaker-puppet.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/deployment/haproxy/haproxy-pacemaker-puppet.yaml b/deployment/haproxy/haproxy-pacemaker-puppet.yaml index 51bb91e5ac..bf8415ff4e 100644 --- a/deployment/haproxy/haproxy-pacemaker-puppet.yaml +++ b/deployment/haproxy/haproxy-pacemaker-puppet.yaml @@ -153,13 +153,13 @@ outputs: list_concat: - if: - public_tls_enabled - - - get_param: HAProxyInternalTLSKeysDirectory - - get_param: HAProxyInternalTLSCertsDirectory - - get_param: DeployedSSLCertificatePath + - - get_param: DeployedSSLCertificatePath - null - if: - internal_tls_enabled - - get_param: InternalTLSCAFile + - get_param: HAProxyInternalTLSKeysDirectory + - get_param: HAProxyInternalTLSCertsDirectory - null tripleo::profile::pacemaker::haproxy_bundle::internal_certs_directory: {get_param: HAProxyInternalTLSCertsDirectory} tripleo::profile::pacemaker::haproxy_bundle::internal_keys_directory: {get_param: HAProxyInternalTLSKeysDirectory}