ironic/install-guide/source/enabling-https.rst
Colleen Murphy 1849a81383 Add SUSE instructions to the install guide
It is true that the existing instructions for other distributions can be
adapted for SUSE, but we can make it even easier by providing
instructions tailored for SUSE.

Change-Id: Id50c3d663fc2bd527ec2fe5e26fd1d4692b971ce
2017-04-18 09:30:43 +02:00

3.0 KiB

Enabling HTTPS

Enabling HTTPS in Swift

The drivers using virtual media use swift for storing boot images and node configuration information (contains sensitive information for Ironic conductor to provision bare metal hardware). By default, HTTPS is not enabled in swift. HTTPS is required to encrypt all communication between swift and Ironic conductor and swift and bare metal (via virtual media). It can be enabled in one of the following ways:

Enabling HTTPS in Image service

Ironic drivers usually use Image service during node provisioning. By default, image service does not use HTTPS, but it is required for secure communication. It can be enabled by making the following changes to /etc/glance/glance-api.conf:

  1. Configuring SSL support

  2. Restart the glance-api service:

    Fedora/RHEL7/CentOS7/SUSE:
        sudo systemctl restart openstack-glance-api
    
    Debian/Ubuntu:
        sudo service glance-api restart

See the Glance documentation, for more details on the Image service.

Enabling HTTPS communication between Image service and Object storage

This section describes the steps needed to enable secure HTTPS communication between Image service and Object storage when Object storage is used as the Backend.

To enable secure HTTPS communication between Image service and Object storage follow these steps:

  1. EnableHTTPSinSwift
  2. Configure Swift Storage Backend
  3. EnableHTTPSinGlance

Enabling HTTPS communication between Image service and Bare Metal service

This section describes the steps needed to enable secure HTTPS communication between Image service and Bare Metal service.

To enable secure HTTPS communication between Bare Metal service and Image service follow these steps:

  1. Edit /etc/ironic/ironic.conf:

    [glance]
    ...
    glance_cafile=/path/to/certfile
    glance_protocol=https
    glance_api_insecure=False

    Note

    'glance_cafile' is a optional path to a CA certificate bundle to be used to validate the SSL certificate served by Image service.

  2. Restart ironic-conductor service:

    Fedora/RHEL7/CentOS7/SUSE:
        sudo systemctl restart openstack-ironic-conductor
    
    Debian/Ubuntu:
        sudo service ironic-conductor restart