Merge "keystone: handle OIDC metadata & attribute mappings as template"

This commit is contained in:
Zuul 2024-12-10 07:52:43 +00:00 committed by Gerrit Code Review
commit 6d9bcfd078
2 changed files with 13 additions and 4 deletions

View File

@ -28,11 +28,11 @@
when: when:
- inventory_hostname in groups[keystone.group] - inventory_hostname in groups[keystone.group]
- name: Copying OpenID Identity Providers metadata - name: Templating OpenID Identity Providers metadata
vars: vars:
keystone: "{{ keystone_services['keystone'] }}" keystone: "{{ keystone_services['keystone'] }}"
become: true become: true
copy: template:
src: "{{ item.metadata_folder }}/" src: "{{ item.metadata_folder }}/"
dest: "{{ keystone_host_federation_oidc_metadata_folder }}" dest: "{{ keystone_host_federation_oidc_metadata_folder }}"
mode: "0660" mode: "0660"
@ -55,11 +55,11 @@
- item.certificate_file is defined - item.certificate_file is defined
- inventory_hostname in groups[keystone.group] - inventory_hostname in groups[keystone.group]
- name: Copying OpenStack Identity Providers attribute mappings - name: Templating OpenStack Identity Providers attribute mappings
vars: vars:
keystone: "{{ keystone_services['keystone'] }}" keystone: "{{ keystone_services['keystone'] }}"
become: true become: true
copy: template:
src: "{{ item.file }}" src: "{{ item.file }}"
dest: "{{ keystone_host_federation_oidc_attribute_mappings_folder }}/{{ item.file | basename }}" dest: "{{ keystone_host_federation_oidc_attribute_mappings_folder }}/{{ item.file | basename }}"
mode: "0660" mode: "0660"

View File

@ -0,0 +1,9 @@
---
features:
- |
In the Keystone role files for the
``keystone_host_federation_oidc_metadata_folder`` and
``keystone_host_federation_oidc_attribute_mappings_folder`` directories
are now handled as templates. This relates to the OpenID Identity Providers
metadata and the OpenStack Identity Providers attribute mappings as part of
the identity federation with OIDC.