Adding ability to specify altnames for vault cert (#1640)

This commit is contained in:
Brad Beam 2017-09-14 01:19:44 -05:00 committed by Matthew Mosesohn
parent 016301508e
commit 4b587aaf99
2 changed files with 6 additions and 1 deletions

View file

@ -83,6 +83,11 @@ vault_ca_options:
format: pem
ttl: "{{ vault_max_lease_ttl }}"
exclude_cn_from_sans: true
altnames:
- "vault.{{ system_namespace }}.svc.{{ dns_domain }}"
- "vault.{{ system_namespace }}.svc"
- "vault.{{ system_namespace }}"
- "vault"
etcd:
common_name: etcd
format: pem

View file

@ -2,7 +2,7 @@
- include: ../shared/issue_cert.yml
vars:
issue_cert_common_name: "{{ vault_pki_mounts.vault.roles[0].name }}"
issue_cert_alt_names: "{{ groups.vault + ['localhost'] }}"
issue_cert_alt_names: "{{ groups.vault + ['localhost'] + vault_ca_options.vault.altnames|default() }}"
issue_cert_hosts: "{{ groups.vault }}"
issue_cert_ip_sans: >-
[