50 Commits (82a28d6bb305b57e8ca90523a44609b870b7b663)

Author SHA1 Message Date
Matthew Mosesohn 97e0de7e29
Fix vault file owner issues and k8s apiserver cert creation (#2985) 6 years ago
Matthew Mosesohn 0b939a495b
Improve vault etcd initialization check (#2959) 6 years ago
Matthew Mosesohn 77c910c1c3
Fixup vault etcd check (#2938) 6 years ago
Matthew Mosesohn 59be578842
Revert "wip pr for improved cert sync" (#2849) 6 years ago
Matthew Mosesohn 7433348aae wip pr for improved cert sync 6 years ago
Matthew Mosesohn 07cc981971
refactor vault role (#2733) 6 years ago
Chad Swenson d87b6fd9f3 Use dedicated front-proxy-ca for front-proxy-client 6 years ago
Matthew Mosesohn 3fa7468d54 Copy ca-key.pem to etcd and kube-masters accordingly 6 years ago
Chen Hong 4a705b3fba May vault health check needs delay 6 years ago
Matthew Mosesohn dc6a17e092
Use include/import tasks (#2192) 6 years ago
Brad Beam d3850a4da5 Fixing alt_names for vault cert generation 6 years ago
Brad Beam 93f3614382 Fixes #2039 - changing alt_names to be string instead of list (#2043) 6 years ago
Julien BONACHERA 290bc993a5
append newline char to vault generated certs 6 years ago
Brad Beam 3694657eb6 Adding retries for vault-init to come online 6 years ago
abelgana fe3290601a
The variable altnames is used by this task. 6 years ago
Spencer Smith 6df104b275 don't check for no_proxy, only http/https_proxy. fix linting issues. 7 years ago
Spencer Smith b27453d8d8 improved proxy support 7 years ago
Peter Lee 0b60201a1e fix etcd health check bug (#1480) 7 years ago
Brad Beam ac281476c8 Prune unnecessary certs from vault setup (#1652) 7 years ago
Brad Beam 4b587aaf99 Adding ability to specify altnames for vault cert (#1640) 7 years ago
Brad Beam 0a89f88b89 Fixing condition where CA already exists 7 years ago
Maxim Krasilnikov e16b57aa05 Store vault users passwords to credentials dir. Create vault and etcd roles after start vault cluster (#1632) 7 years ago
mkrasilnikov 957b7115fe Remove node name from kube-proxy and admin certificates 7 years ago
mkrasilnikov b930b0ef5a Place vault role credentials only to vault group hosts 7 years ago
mkrasilnikov ad313c9d49 typo fix 7 years ago
mkrasilnikov e1384f6618 Using issue cert result var instead hostvars 7 years ago
mkrasilnikov 3acb86805b Rename vault_address to vault_bind_address 7 years ago
mkrasilnikov bf0af1cd3d Vault role updates: 7 years ago
Brad Beam 8ae77e955e Adding in certificate serial numbers to manifests (#1392) 7 years ago
Maxim Krasilnikov 6eb22c5db2 Change single Vault pki mount to multi pki mounts paths for etcd and kube CA`s (#1552) 7 years ago
Brad Beam 4550dccb84 Fixing reference to vault leader url (#1569) 7 years ago
Brad Beam 8b151d12b9 Adding yamllinter to ci steps (#1556) 7 years ago
Maxim Krasilnikov 2ba285a544 Fixed deploy cluster with vault cert manager (#1548) 7 years ago
Matthew Mosesohn 2645e88b0c Fix vault setup partially (#1531) 7 years ago
Anton e0960f6288 FIX: Unneded (extra) cycles in some tasks (#1393) 7 years ago
Anton Nerozya 1fedbded62 ignore_errors instead of failed_when: false 7 years ago
Anton Nerozya c8258171ca Better naming for recurrent tasks 7 years ago
Brad Beam db3e8edacd Fixing up vault variables 7 years ago
Sergii Golovatiuk 674b71b535 Ansible 2.3 support 7 years ago
Matthew Mosesohn d7b8fb3113 Update start_vault_temp.yml 7 years ago
Matthew Mosesohn ae7f59e249 Skip vault cert task evaluation completely when using script cert generation 7 years ago
Matthew Mosesohn 45274560ec Disable vault role properly on ansible 2.2.0 7 years ago
Andrew Greenwood ca9ea097df Cleanup legacy syntax, spacing, files all to yml 7 years ago
Matthew Mosesohn 80c0e747a7 Fix references to CoreOS and Container Linux by CoreOS 7 years ago
Josh Conant 245e05ce61 Vault security hardening and role isolation 7 years ago
Josh Conant f4ec2d18e5 Adding the Vault role 7 years ago