|
| 1 | +--- |
| 2 | +# User Configuration Template for HSM Adoption |
| 3 | +# Copy this file to user_config.yml and customize all values |
| 4 | +# |
| 5 | +# IMPORTANT: Replace ALL values marked with CHANGE_ME_* |
| 6 | + |
| 7 | +# ============================================ |
| 8 | +# ENVIRONMENT CONFIGURATION |
| 9 | +# ============================================ |
| 10 | +user_kubeconfig_path: "CHANGE_ME_KUBECONFIG_PATH" # e.g., "/home/user/.kube/config" |
| 11 | +user_oc_path: "CHANGE_ME_OC_PATH" # e.g., "/usr/local/bin" |
| 12 | +user_target_namespace: "CHANGE_ME_NAMESPACE" # e.g., "openstack" |
| 13 | +user_internal_api_prefix: "CHANGE_ME_API_PREFIX" # e.g., "172.17.0" |
| 14 | + |
| 15 | +# ============================================ |
| 16 | +# CONTAINER REGISTRY CONFIGURATION |
| 17 | +# ============================================ |
| 18 | +user_image_registry: "CHANGE_ME_REGISTRY" # e.g., "quay.io" or "registry.example.com" |
| 19 | +user_image_namespace: "CHANGE_ME_NAMESPACE" # e.g., "your_org/barbican" |
| 20 | +user_image_tag: "CHANGE_ME_TAG" # e.g., "latest-proteccio" |
| 21 | +user_api_image_name: "CHANGE_ME_API_IMAGE" # e.g., "openstack-barbican-api" |
| 22 | +user_worker_image_name: "CHANGE_ME_WORKER_IMAGE" # e.g., "openstack-barbican-worker" |
| 23 | + |
| 24 | +# ============================================ |
| 25 | +# PROTECCIO HSM CONFIGURATION |
| 26 | +# ============================================ |
| 27 | +user_proteccio_tokens: "CHANGE_ME_TOKEN_LIST" # e.g., ["TOKEN1", "TOKEN2"] |
| 28 | +user_proteccio_mkek: "CHANGE_ME_MKEK_LABEL" # e.g., "my_mkek_label" |
| 29 | +user_proteccio_hmac: "CHANGE_ME_HMAC_LABEL" # e.g., "my_hmac_label" |
| 30 | +user_proteccio_password: "CHANGE_ME_HSM_PASSWORD" # Your HSM login password |
| 31 | +user_proteccio_lib_path: "CHANGE_ME_LIB_PATH" # e.g., "/opt/tw_proteccio/lib/libnethsm.so" |
| 32 | + |
| 33 | +# ============================================ |
| 34 | +# PROTECCIO FILE PATHS |
| 35 | +# ============================================ |
| 36 | +user_proteccio_certs_path: "CHANGE_ME_CERTS_PATH" # e.g., "/opt/proteccio/certs" |
| 37 | +user_proteccio_config_path: "CHANGE_ME_CONFIG_PATH" # e.g., "/opt/proteccio" |
| 38 | +user_proteccio_iso_path: "CHANGE_ME_ISO_PATH" # e.g., "/opt/proteccio" |
| 39 | +user_proteccio_iso: "CHANGE_ME_ISO_FILENAME" # e.g., "Proteccio3.06.05.iso" |
| 40 | +user_proteccio_config: "CHANGE_ME_CONFIG_FILE" # e.g., "proteccio.rc" |
| 41 | + |
| 42 | +# ============================================ |
| 43 | +# KUBERNETES SECRETS |
| 44 | +# ============================================ |
| 45 | +user_proteccio_login_secret: "CHANGE_ME_LOGIN_SECRET" # e.g., "hsm-login" |
| 46 | +user_proteccio_data_secret: "CHANGE_ME_DATA_SECRET" # e.g., "proteccio-data" |
| 47 | +user_proteccio_data_path: "CHANGE_ME_DATA_PATH" # e.g., "/etc/proteccio" |
| 48 | + |
| 49 | +# ============================================ |
| 50 | +# SERVICE CONFIGURATION |
| 51 | +# ============================================ |
| 52 | +user_api_replicas: "CHANGE_ME_API_REPLICAS" # e.g., 2 |
| 53 | +user_worker_replicas: "CHANGE_ME_WORKER_REPLICAS" # e.g., 2 |
| 54 | +user_keystone_replicas: "CHANGE_ME_KS_REPLICAS" # e.g., 2 |
| 55 | +user_default_secret_store: "CHANGE_ME_DEFAULT_STORE" # e.g., "pkcs11" |
| 56 | +user_enabled_stores: "CHANGE_ME_ENABLED_STORES" # e.g., ["simple_crypto", "pkcs11"] |
| 57 | + |
| 58 | +# ============================================ |
| 59 | +# ANSIBLE ROLE CONFIGURATION |
| 60 | +# ============================================ |
| 61 | +user_proteccio_role: "CHANGE_ME_ROLE_NAME" # e.g., "ansible-role-rhoso-proteccio-hsm" |
| 62 | + |
| 63 | +# ============================================ |
| 64 | +# OUTPUT CONFIGURATION |
| 65 | +# ============================================ |
| 66 | +user_create_summary: "CHANGE_ME_CREATE_SUMMARY" # e.g., true |
| 67 | +user_summary_path: "CHANGE_ME_SUMMARY_PATH" # e.g., "/tmp/adoption_summary.md" |
0 commit comments