Advertisement
coldbeer101

Untitled

Aug 15th, 2018
185
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.65 KB | None | 0 0
  1. Octavia Config:
  2. [DEFAULT]
  3. debug = True
  4. transport_url = rabbit://xxxx:xxxx@openstack-galera1.sdsc.edu:5672,xxx:xxxx@openstack-galera2.sdsc.edu:5672/
  5. log_file=/var/log/octavia/octavia.log
  6. log_dir=/var/log/octavia
  7. [api_settings]
  8. [database]
  9. connection = mysql+pymysql://octavia:xxxxxx@openstack-galera.sdsc.edu/octavia?charset=utf8
  10. [health_manager]
  11. bind_ip = 0.0.0.0
  12. controller_ip_port_list =10.10.0.8:5555,10.10.0.14:5555
  13. heartbeat_key =xxxxxx
  14. [keystone_authtoken]
  15. auth_uri = http://identity-int.cloud.sdsc.edu:5000
  16. auth_url = http://identity-int.cloud.sdsc.edu:35357
  17. username = octavia
  18. password = NdB40s1m
  19. project_name = service
  20. project_domain_name = default
  21. user_domain_name = default
  22. auth_type=password
  23. memcached_servers=openstack-controller1.sdsc.edu:11211,openstack-controller2.sdsc.edu:11211
  24. region_name=SDSC
  25. [certificates]
  26. ca_certificate = /etc/pki/tls/certs/octavia_server_ca.pem
  27. ca_private_key = /etc/pki/tls/private/octavia_server_ca.key
  28. ca_private_key_passphrase =xxxxx
  29. [anchor]
  30. [networking]
  31. [haproxy_amphora]
  32. client_cert = /etc/pki/tls/certs/octavia_client_cert.pem
  33. server_ca = /etc/pki/tls/certs/octavia_client_ca.pem
  34. [controller_worker]
  35. amp_active_retries = 50
  36. amp_active_wait_sec = 10
  37. amp_image_tag =octavia-amphora-image
  38. amp_flavor_id =5d5a2106-e74c-4488-843f-1a7bbcb146d9
  39. amp_ssh_key_name =octavia_key
  40. amp_boot_network_list =09d14821-e471-4548-a57f-5b29b33de0d7
  41. amp_secgroup_list =54d35af1-25e9-47d3-872d-9829a5783930
  42. client_ca = /etc/pki/tls/certs/octavia_client_ca.pem
  43. amphora_driver = amphora_haproxy_rest_driver
  44. compute_driver = compute_nova_driver
  45. network_driver = allowed_address_pairs_driver
  46. [task_flow]
  47. disable_revert = True
  48. [oslo_messaging]
  49. topic = octavia-rpc
  50. [house_keeping]
  51. [amphora_agent]
  52. [keepalived_vrrp]
  53. [service_auth]
  54. project_domain_name = default
  55. project_name = service
  56. user_domain_name = default
  57. password = xxxx
  58. username = octavia
  59. auth_type = password
  60. auth_url = http://identity-int.cloud.sdsc.edu:5000/
  61. [nova]
  62. [glance]
  63. [neutron]
  64. [quotas]
  65. [oslo_messaging_notifications]
  66. transport_url=rabbit://xxxx:xxx@openstack-galera1:5672,xxxx:xxxx@openstack-galera2:5672/
  67.  
  68. My curl command from worker (that does not generate any SSL errors):
  69. curl --cacert /etc/pki/tls/certs/octavia_server_ca.pem --key /etc/pki/tls/private/octavia_server_ca.key --pass xxx --resolve 'eb2ba854-d38f-4100-b5dc-578c1db556ac:9443:10.10.0.7' --verbose https://eb2ba854-d38f-4100-b5dc-578c1db556ac:9443/0.5/info
  70. * Added eb2ba854-d38f-4100-b5dc-578c1db556ac:9443:10.10.0.7 to DNS cache
  71. * About to connect() to eb2ba854-d38f-4100-b5dc-578c1db556ac port 9443 (#0)
  72. * Trying 10.10.0.7...
  73. * Connected to eb2ba854-d38f-4100-b5dc-578c1db556ac (10.10.0.7) port 9443 (#0)
  74. * Initializing NSS with certpath: sql:/etc/pki/nssdb
  75. * CAfile: /etc/pki/tls/certs/octavia_server_ca.pem
  76. CApath: none
  77. * NSS: client certificate not found (nickname not specified)
  78. * SSL connection using TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  79. * Server certificate:
  80. * subject: CN=eb2ba854-d38f-4100-b5dc-578c1db556ac
  81. * start date: Aug 14 20:45:58 2018 GMT
  82. * expire date: Aug 13 20:45:58 2020 GMT
  83. * common name: eb2ba854-d38f-4100-b5dc-578c1db556ac
  84. * issuer: CN=octavia_server_ca.cloud.sdsc.edu,O=San Diego Supercomputer Center,L=La Jolla,ST=California,C=US
  85. > GET /0.5/info HTTP/1.1
  86. > User-Agent: curl/7.29.0
  87. > Host: eb2ba854-d38f-4100-b5dc-578c1db556ac:9443
  88. > Accept: */*
  89. >
  90. < HTTP/1.1 200 OK
  91. < Server: gunicorn/19.9.0
  92. < Date: Wed, 15 Aug 2018 17:38:57 GMT
  93. < Connection: close
  94. < Content-Type: application/json
  95. < Content-Length: 116
  96. <
  97. * Closing connection 0
  98. {"haproxy_version":"1.6.3-1ubuntu0.1","api_version":"0.5","hostname":"amphora-eb2ba854-d38f-4100-b5dc-578c1db556ac"}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement