Deprecate allow_insecure_clients option

The allow_insecure_clients has been deprecated[1].

[1]https://review.opendev.org/#/c/417629/

Change-Id: I4c1193bf8359ce02e6b1e9438f26d87c44c3b1a4
Closes-Bug: #1902158
This commit is contained in:
ZhongShengping 2020-11-02 14:42:04 +08:00
parent 78b932cef2
commit ec2d0a847f
3 changed files with 29 additions and 22 deletions

View File

@ -147,10 +147,6 @@
# (optional) Password for decrypting ssl_key_file (if encrypted)
# Defaults to $::os_service_default
#
# [*amqp_allow_insecure_clients*]
# (optional) Accept clients using either SSL or plain TCP
# Defaults to false
#
# [*amqp_sasl_mechanisms*]
# (Optional) Space separated list of acceptable SASL mechanisms
# Defaults to $::os_service_default.
@ -222,6 +218,10 @@
# (optional) If set, use this value for max_overflow with sqlalchemy.
# Defaults to undef.
#
# [*amqp_allow_insecure_clients*]
# (optional) Accept clients using either SSL or plain TCP
# Defaults to undef.
#
class manila (
$default_transport_url = $::os_service_default,
$rpc_response_timeout = $::os_service_default,
@ -254,7 +254,6 @@ class manila (
$amqp_container_name = 'guest',
$amqp_idle_timeout = '0',
$amqp_trace = false,
$amqp_allow_insecure_clients = false,
$amqp_ssl_ca_file = $::os_service_default,
$amqp_ssl_cert_file = $::os_service_default,
$amqp_ssl_key_file = $::os_service_default,
@ -274,12 +273,18 @@ class manila (
$database_retry_interval = undef,
$database_max_pool_size = undef,
$database_max_overflow = undef,
$amqp_allow_insecure_clients = undef,
) {
include manila::deps
include manila::db
include manila::params
if $amqp_allow_insecure_clients != undef {
warning('The amqp_allow_insecure_clients parameter is deprecated and \
will be removed in a future release.')
}
if $sql_connection != undef {
warning('The sql_connection parameter is deprecated and will be \
removed in a future realse. Use manila::db::database_connection instead')
@ -344,22 +349,21 @@ removed in a future realse. Use manila::db::database_max_overflow instead')
}
oslo::messaging::amqp { 'manila_config':
server_request_prefix => $amqp_server_request_prefix,
broadcast_prefix => $amqp_broadcast_prefix,
group_request_prefix => $amqp_group_request_prefix,
container_name => $amqp_container_name,
idle_timeout => $amqp_idle_timeout,
trace => $amqp_trace,
allow_insecure_clients => $amqp_allow_insecure_clients,
ssl_ca_file => $amqp_ssl_ca_file,
ssl_key_password => $amqp_ssl_key_password,
ssl_cert_file => $amqp_ssl_cert_file,
ssl_key_file => $amqp_ssl_key_file,
sasl_mechanisms => $amqp_sasl_mechanisms,
sasl_config_dir => $amqp_sasl_config_dir,
sasl_config_name => $amqp_sasl_config_name,
username => $amqp_username,
password => $amqp_password,
server_request_prefix => $amqp_server_request_prefix,
broadcast_prefix => $amqp_broadcast_prefix,
group_request_prefix => $amqp_group_request_prefix,
container_name => $amqp_container_name,
idle_timeout => $amqp_idle_timeout,
trace => $amqp_trace,
ssl_ca_file => $amqp_ssl_ca_file,
ssl_key_password => $amqp_ssl_key_password,
ssl_cert_file => $amqp_ssl_cert_file,
ssl_key_file => $amqp_ssl_key_file,
sasl_mechanisms => $amqp_sasl_mechanisms,
sasl_config_dir => $amqp_sasl_config_dir,
sasl_config_name => $amqp_sasl_config_name,
username => $amqp_username,
password => $amqp_password,
}
oslo::messaging::default { 'manila_config':

View File

@ -0,0 +1,4 @@
---
deprecations:
- allow_insecure_clients option is now deprecated for removal, the
parameter has no effect.

View File

@ -222,7 +222,6 @@ describe 'manila' do
it { is_expected.to contain_manila_config('oslo_messaging_amqp/container_name').with_value('guest') }
it { is_expected.to contain_manila_config('oslo_messaging_amqp/idle_timeout').with_value('0') }
it { is_expected.to contain_manila_config('oslo_messaging_amqp/trace').with_value(false) }
it { is_expected.to contain_manila_config('oslo_messaging_amqp/allow_insecure_clients').with_value(false) }
it { is_expected.to contain_manila_config('oslo_messaging_amqp/ssl_key_password').with_value('<SERVICE DEFAULT>')}
it { is_expected.to contain_manila_config('oslo_messaging_amqp/ssl_ca_file').with_value('<SERVICE DEFAULT>')}
it { is_expected.to contain_manila_config('oslo_messaging_amqp/ssl_cert_file').with_value('<SERVICE DEFAULT>')}