-
Notifications
You must be signed in to change notification settings - Fork 313
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
make gossip encryption optional fixes #126 #127
Conversation
register: consul_keygen | ||
|
||
- name: Write key locally to share with other nodes | ||
- block: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
i just indented the whole part and wrapped a block around it
defaults/main.yml
Outdated
@@ -142,6 +142,9 @@ consul_acl_master_token_display: "{{ lookup('env','CONSUL_ACL_MASTER_TOKEN_DISPL | |||
consul_acl_replication_enable: "{{ lookup('env','CONSUL_ACL_REPLICATION_ENABLE') | default('',true) }}" | |||
consul_acl_replication_token: "{{ lookup('env','CONSUL_ACL_REPLICATION_TOKEN') | default('', true) }}" | |||
|
|||
## gossip encryption | |||
consul_encrypt_enable: "{{ lookup('env','CONSUL_TLS_ENABLE') | default(true, true) }}" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Perhaps this Ansible variable can also have its own environment variable, like CONSUL_ENCRYPT_ENABLE
for example instead of using CONSUL_TLS_ENABLE
?
Oh, 🙈 sure I will fix this.
…On Wed, 22 Nov 2017, 19:36 Brian Shumate, ***@***.***> wrote:
***@***.**** requested changes on this pull request.
------------------------------
In defaults/main.yml
<#127 (comment)>
:
> @@ -142,6 +142,9 @@ consul_acl_master_token_display: "{{ lookup('env','CONSUL_ACL_MASTER_TOKEN_DISPL
consul_acl_replication_enable: "{{ lookup('env','CONSUL_ACL_REPLICATION_ENABLE') | default('',true) }}"
consul_acl_replication_token: "{{ lookup('env','CONSUL_ACL_REPLICATION_TOKEN') | default('', true) }}"
+## gossip encryption
+consul_encrypt_enable: "{{ lookup('env','CONSUL_TLS_ENABLE') | default(true, true) }}"
Perhaps this Ansible variable can also have its own environment variable,
like CONSUL_ENCRYPT_ENABLE for example instead of using CONSUL_TLS_ENABLE?
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#127 (review)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AAENANB_JgX8rjZLDrGleGbWkembJ92Bks5s5GmTgaJpZM4QntqK>
.
|
Thank you! |
I added a new variable
consul_encrypt_enable
.The default value will not change anything, but if you set it to false it will skip all parts that are handling gossip encryption stuff.