Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1848153

Summary: etcd not using TLS when deployed with TLS-everywhere
Product: Red Hat OpenStack Reporter: Alan Bishop <abishop>
Component: openstack-tripleo-heat-templatesAssignee: Alan Bishop <abishop>
Status: CLOSED ERRATA QA Contact: Tzach Shefi <tshefi>
Severity: medium Docs Contact:
Priority: high    
Version: 16.1 (Train)CC: gcharot, gfidente, hrybacki, jamsmith, mburns, mkrcmari, pgrist, rheslop, spower
Target Milestone: AlphaKeywords: Triaged, ZStream
Target Release: 17.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-tripleo-heat-templates-14.3.1-0.20210912021828.e7f8587.el8ost Doc Type: Enhancement
Doc Text:
With this update, you can now use Red Hat OpenStack Platform director to configure the etcd service to use TLS endpoints when deploying TLS-everywhere.
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-09-21 12:10:46 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1823932, 1855403, 1859750    
Bug Blocks:    

Description Alan Bishop 2020-06-17 19:48:43 UTC
In order to work around early issues encountered with cinder trying to use etcd for its distributed lock manager in a tls-e deployment, a new THT parameter was introduced by [1] that controls whether etcd (and cinder) actually use TLS.

[1] https://review.opendev.org/717837

The new EnableEtcdInternalTLS defaults to False. Full support for TLS is possible when tls-e is deployed using tripleo-ipa (see bug #1823932), but that is not the default tls-e deployment in Train. Train still defaults to using novajoin, which needs to be fixed in order for etcd to support TLS (see bug #1843701).

In other words, once bug #1843701 is fixed it will be possible to deploy etcd with TLS. At that point, the EnableEtcdInternalTLS should default to True.

Comment 17 errata-xmlrpc 2022-09-21 12:10:46 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Release of components for Red Hat OpenStack Platform 17.0 (Wallaby)), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:6543