Skip to content

Add certs for IoP#501

Merged
ehelms merged 1 commit intotheforeman:masterfrom
ehelms:add-iop-certs
Jul 11, 2025
Merged

Add certs for IoP#501
ehelms merged 1 commit intotheforeman:masterfrom
ehelms:add-iop-certs

Conversation

@ehelms
Copy link
Member

@ehelms ehelms commented Jul 9, 2025

This add server and client certificates to be used by the IoP Gateway. This does not remove the iop_advisor_engine certificates yet as those should be cleaned up after switching implementation.

Copy link

@vkrizan vkrizan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@@ -0,0 +1,99 @@
# Contains certs specific configurations for IOP
class certs::iop (
Stdlib::Fqdn $hostname = 'localhost',
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So we're keeping the localhostness.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Otherwise we have to expose the Gateway on the public interface which I believe we wanted to avoid.

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was thinking of an alternative, to create a custom name in /etc/hosts for it that would point to local interface.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's the value you are thinking?

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No value, just cosmetics. As it would look like a link to something external (that it technically can be). Having a specific name could distinguish other local services, if needed.

Just a suggestion for future. No need to change this.

@ehelms ehelms force-pushed the add-iop-certs branch 2 times, most recently from deba512 to 5955a9f Compare July 10, 2025 15:23
Signed-off-by: Eric D. Helms <ericdhelms@gmail.com>
@ehelms ehelms merged commit dc129fc into theforeman:master Jul 11, 2025
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Comments