Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1558236 - [Deployment][TLS] TLS ODL container deployments fail due to no odl user/group on host
[Deployment][TLS] TLS ODL container deployments fail due to no odl user/group...
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: puppet-tripleo (Show other bugs)
13.0 (Queens)
Unspecified Unspecified
urgent Severity high
: beta
: 13.0 (Queens)
Assigned To: Tim Rozet
Itzik Brown
odl_deployment, odl_tls
: Triaged
Depends On:
Blocks: 1488826
  Show dependency treegraph
 
Reported: 2018-03-19 17:05 EDT by Tim Rozet
Modified: 2018-10-18 03:24 EDT (History)
6 users (show)

See Also:
Fixed In Version: puppet-tripleo-8.3.1-0.20180304033909
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
N/A
Last Closed: 2018-06-27 09:47:45 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Launchpad 1757135 None None None 2018-03-20 09:19 EDT
OpenStack gerrit 554537 None None None 2018-03-20 09:33 EDT
OpenStack gerrit 554909 None None None 2018-03-23 09:40 EDT
Red Hat Product Errata RHEA-2018:2086 None None None 2018-06-27 09:49 EDT

  None (edit)
Description Tim Rozet 2018-03-19 17:05:04 EDT
Description of problem:
In TLS deployments a key and certificate are created for ODL on the host (as owner/group odl/odl).  These artifacts are then used to configure TLS for ODL.  In containerized deployments these files are still created on the host, and then mounted into the ODL container.  However, now that we containerize ODL, it means the RPM is no longer installed on the host, and the 'odl' linux group/user are not created.  Thus when deploying with TLS and ODL, there is a puppet error saying:

            "Error: /Stage[main]/Tripleo::Certmonger::Opendaylight/File[/etc/pki/tls/certs/odl.crt]/group: change from root to odl failed: Could not find group odl",                            
            "Error: /Stage[main]/Tripleo::Certmonger::Opendaylight/File[/etc/pki/tls/private/odl.key]/owner: change from root to odl failed: Could not find user odl",                           
            "Error: /Stage[main]/Tripleo::Certmonger::Opendaylight/File[/etc/pki/tls/private/odl.key]/group: change from root to odl failed: Could not find group odl"    

Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1.  Deploy ODL with internal TLS enabled and containers
2.
3.

Actual results:


Expected results:


Additional info:
A workaround to this issue is to virt-customize the overcloud image and install ODL on it to get the user/group created.
Comment 7 Itzik Brown 2018-04-26 05:35:57 EDT
Checked with:
puppet-tripleo-8.3.2-0.20180416191414.cb114de.el7ost.noarch
Comment 9 errata-xmlrpc 2018-06-27 09:47:45 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2018:2086

Note You need to log in before you can comment on or make changes to this bug.