Skip to content

Commit e326d3c

Browse files
authored
Merge pull request #379 from NETWAYS/feature/redis-tls
Add setting for Redis clients certificates
2 parents f5f30e3 + 58a3159 commit e326d3c

File tree

4 files changed

+10
-1
lines changed

4 files changed

+10
-1
lines changed
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
3+
minor_changes:
4+
- "Add variable :code:`icingadb_redis_client_certificate` to define whether TLS client certificates are accepted/required/rejected when connecting to the Redis server. Only has an effect when using TLS encryption."

roles/icingadb/templates/icingadb.ini.j2

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,10 @@ database:
3030

3131
redis:
3232
host: {{ icingadb_redis_host }}
33-
{% if icingadb_redis_port is defined %}
33+
{% if icingadb_redis_tls is defined %}
34+
port: 0
35+
tls-port: {{ icingadb_redis_tls_port | default(6380) }}
36+
{% elif icingadb_redis_port is defined %}
3437
port: {{ icingadb_redis_port }}
3538
{% endif %}
3639
{% if icingadb_redis_password is defined %}

roles/icingadb_redis/defaults/main.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,3 +65,4 @@ icingadb_redis_rdb_save_incremental_fsync: 'yes'
6565
#icingadb_redis_tls_cert: /etc/ssl/certs/host.crt
6666
#icingadb_redis_tls_key: /etc/ssl/private/host.key
6767
#icingadb_redis_tls_ca: /etc/ssl/certs/root-ca.crt
68+
icingadb_redis_client_certificate: "yes"

roles/icingadb_redis/templates/icingadb-redis.conf.j2

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -227,4 +227,5 @@ rdb-save-incremental-fsync {{ icingadb_redis_rdb_save_incremental_fsync }}
227227
tls-cert-file {{ icingadb_redis_tls_cert }}
228228
tls-key-file {{ icingadb_redis_tls_key }}
229229
tls-ca-cert-file {{ icingadb_redis_tls_ca }}
230+
tls-auth-clients {{ icingadb_redis_client_certificate }}
230231
{% endif %}

0 commit comments

Comments
 (0)