adriano-di-giovanni.consul-tls
Ansible Role: Consul TLS
Generates self-signed OpenSSL certificates to be used by Consul for RPC encryption with TLS.
Requirements
- OpenSSL
Role Variables
# Where to put output certificates
consul_tls_out_dir: ~/.consul_tls
# Number of days certificates are valid for
consul_tls_default_days: '{{ 365 * 10 }}'
# Datacenter for consul cluster using generated certificates
consul_datacenter: default
Dependencies
None.
Example Playbook
This role is meant to be run locally.
---
- hosts: localhost
connection: local
roles:
- role: adriano-di-giovanni.consul-tls
consul_tls_out_dir: /tmp/consul_tls
consul_datacenter: dc1
Run the example playbook to create
ca.crt.pemdc1.consul.key.pemdc1.consul.crt.pem
in /tmp/consul_tls.
Upload the files to consul nodes and change configuration as follows:
{
"ca_file": "/opt/consul/tls/ca.crt.pem",
"cert_file": "/opt/consul/tls/dc1.consul.crt.pem",
"key_file": "/opt/consul/tls/dc1.consul.key.pem",
"verify_incoming": true,
"verify_outgoing": true,
"verify_server_hostname": true
}
License
MIT
Author Information
Adriano Di Giovanni
About
Ansible role for generating self-signed OpenSSL certificates to be used by Consul for RPC encryption with TLS
Install
ansible-galaxy install adriano-di-giovanni.consul-tlsLicense
mit
Downloads
129
Owner
Senior software consultant with 28 years of experience, specializing in Software Product Engineering. Well-versed in the entire Software Development Life Cycle
