...
So, to implement goal of this feature, K8s plugin must be enhanced to support following new blueprint properties in new external_cert section and extra properties in K8s plugin configuration listed in following table:
Code Block |
---|
external_cert: use_external_tls external_cert_directory imageca_tagname request_urlexternal_certificate_parameters: timeout cacommon_name common_name sans country organization state organizational_unit location |
Meaning of properties is described in following table. CertService's client properties are described in details on a dedicated page.
...
Group | Property name | Type (input*/blueprint**/plugin***) | Default | Description |
---|---|---|---|---|
external_cert | use_external_tls | input | true | A boolean that indicates whether the component uses AAF CertService to acquire operator certificate to protect external (between xNFs and ONAP) traffic. For a time being only operator certificate from CMPv2 server is supported |
external_cert_directory | blueprint | /opt/app/dcae-certificate/external_cert | Directory where operator certificate and trusted certs should be created | |
image_tag | plugin | nexus3.onap.org:10001/onap/org.onap.aaf.certservice.aaf-certservice-client:$VERSION | Image name and version | |
request_url | plugin | https://aaf-cert-service-service:8443/v1/certificate/URL to Cert Service API | ||
timeout | plugin | 30000 | Request timeout | |
ca_name | input | RA_TEST | Name of Certificate Authority configured on CertService side (in cmpServers.json). Default RA_TEST corresponds to default CMPv2 testing configuration. | |
external_cert: external_certificate_parameters | common_name | input | <Specific for every blueprint> | Common name which should be present in certificate. Specific for every blueprint (e.g. dcae-ves-collector for VES) |
sans | input | <Specific for every blueprint> | List of Subject Alternative Names (SANs) which should be present in certificate. Delimiter - : Should contain common_name value and other FQDNs under which given component is accessible, e.g. if xNFs uses ves-collector in request URL, such should be also present in SANs - e.g. dcae-ves-collector:ves-collector. | |
country | input | US | Country name in ISO 3166-1 alpha-2 format, for which certificate will be created | |
organization | input | Linux-Foundation | Organization name, for which certificate will be created | |
state | input | California | State name, for which certificate will be created | |
organizational_unit | input | ONAP | Organizational unit name, for which certificate will be created | |
location | input | San-Francisco | Location name, for which certificate will be created | |
Extra K8s plugin configuration parameters | ||||
image_tag | plugin | nexus3.onap.org:10001/onap/org.onap.aaf.certservice.aaf-certservice-client:$VERSION | Image name and version | |
request_url | plugin | https://aaf-cert-service-service:8443/v1/certificate/ | URL to Cert Service API | |
timeout | plugin | 30000 | Request timeout |
If new properties are provided by blueprint and use_external_tls is set to true, K8s plugin must be able to create init containers section and within it add information about CertService's client image and pass all other variables as environment variables. Very similar to example described on a dedicated page.
...