Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1432845

Summary: [DOCS] Include the logging deployment parameters about custom cert in doc
Product: OpenShift Container Platform Reporter: Xia Zhao <xiazhao>
Component: DocumentationAssignee: Brandi Munilla <bmcelvee>
Status: CLOSED CURRENTRELEASE QA Contact: Xia Zhao <xiazhao>
Severity: medium Docs Contact: Vikram Goyal <vigoyal>
Priority: medium    
Version: 3.5.0CC: aos-bugs, bmcelvee, ewolinet, jokerman, mmccomas
Target Milestone: ---Keywords: NeedsTestCase
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-05-01 20:41:50 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Xia Zhao 2017-03-16 08:52:45 UTC
Description of problem:
Need to include the logging deployment parameters [2] into doc [1]
[1]https://github.com/openshift/openshift-ansible/tree/master/roles/openshift_logging
[2]
openshift_logging_kibana_cert
openshift_logging_kibana_key
openshift_logging_kibana_ca

Version-Release number of selected component (if applicable):
https://github.com/openshift/openshift-ansible/tree/master/roles/openshift_logging

How reproducible:
Always

Steps to Reproduce:
1.Refer to "Description of problem"
2.
3.

Actual results:


Expected results:


Additional info:

Comment 1 Xia Zhao 2017-03-16 09:33:38 UTC
And from code, kibana and kibana-ops is using same cert:
https://github.com/openshift/openshift-ansible/blob/dab7c7d035d0a934d9d7f809ddcbfb34913042a4/roles/openshift_logging/tasks/generate_routes.yaml#L36

May need to mention in doc, since previously we used separate parameters "kibana.crt,kibana-ops.crt" for the deployer: https://docs.openshift.com/container-platform/3.4/install_config/aggregate_logging.html

@ewolinet, could you please help confirm the above changes? Thanks!

Comment 2 ewolinet 2017-03-16 19:24:01 UTC
@Xia that looks to be a regression if we don't provide a means to specify separate kibana-ops certs.

Comment 4 Ashley Hardin 2017-03-27 18:38:43 UTC
Work in progress: https://github.com/openshift/openshift-docs/pull/4037

Comment 5 Xia Zhao 2017-03-30 02:46:19 UTC
(In reply to ewolinet from comment #2)
> @Xia that looks to be a regression if we don't provide a means to specify
> separate kibana-ops certs.

Thanks for the confirmation, Eric. Tested with the new parameters about custom certs for ops clusters, passed verification with openshift-ansible-3.5.45-1.git.1.4ebc840.el7.noarch:

openshift_logging_kibana_cert
openshift_logging_kibana_key
openshift_logging_kibana_ca
openshift_logging_kibana_ops_cert
openshift_logging_kibana_ops_key
openshift_logging_kibana_ops_ca

After deploying logging with ansible, both the kibana and kibana-ops routes are accessible with log entries presented.