Skip to content

Commit 638d972

Browse files
committed
don't use static oauth keys, generate them during deployment
1 parent e32c527 commit 638d972

File tree

2 files changed

+5
-2
lines changed

2 files changed

+5
-2
lines changed

src/vars/base.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,6 @@ candlepin_client_certificate: "{{ client_certificate }}"
1818
foreman_ca_certificate: "{{ server_ca_certificate }}"
1919
foreman_client_key: "{{ client_key }}"
2020
foreman_client_certificate: "{{ client_certificate }}"
21-
foreman_oauth_consumer_key: abcdefghijklmnopqrstuvwxyz123456
22-
foreman_oauth_consumer_secret: abcdefghijklmnopqrstuvwxyz123456
2321
foreman_plugins: "{{ enabled_features | features_to_foreman_plugins }}"
2422
foreman_url: "https://{{ ansible_facts['fqdn'] }}"
2523

src/vars/foreman.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,8 @@
22
foreman_admin_passwd_file: "{{ obsah_state_path }}/foreman-admin-init-passwd"
33
foreman_initial_admin_username: admin
44
foreman_initial_admin_password: "{{ lookup('ansible.builtin.password', foreman_admin_passwd_file, chars=['ascii_letters']) }}"
5+
6+
foreman_oauth_consumer_key_file: "{{ obsah_state_path }}/foreman-oauth-consumer-key"
7+
foreman_oauth_consumer_key: "{{ lookup('ansible.builtin.password', foreman_oauth_consumer_key_file, chars=['ascii_letters', 'digits'], length=32) }}"
8+
foreman_oauth_consumer_secret_file: "{{ obsah_state_path }}/foreman-oauth-consumer-secret"
9+
foreman_oauth_consumer_secret: "{{ lookup('ansible.builtin.password', foreman_oauth_consumer_secret_file, chars=['ascii_letters', 'digits'], length=32) }}"

0 commit comments

Comments
 (0)