diff --git a/data_bags/credentials/redis.json b/data_bags/credentials/redis.json index 594a2e7..8325e52 100644 --- a/data_bags/credentials/redis.json +++ b/data_bags/credentials/redis.json @@ -1,9 +1,9 @@ { "id": "redis", "password": { - "encrypted_data": "M2Cr7oNhL735D3coHnMc9yLuUzYlhkl+TfyMx1ccplFOyVZ+fXRF9UdDqxJ2\nyFIDJ+Yg\n", - "iv": "nEQz0SCUuFAEmxMd\n", - "auth_tag": "uuwSJdMZfLcRs7yjVrRlAQ==\n", + "encrypted_data": "vboNGwFD8JtX4d6Y6lTN4L/BXy1K1GWziX5S28Pm2/anH6Zydyjh3dvlmz1F\nXgddVQ==\n", + "iv": "5YH4k07V3t6dDajR\n", + "auth_tag": "k8ISunt4kgQ/WDB9aPS8kg==\n", "version": 3, "cipher": "aes-256-gcm" } diff --git a/site-cookbooks/kosmos-akkounts/CHANGELOG.md b/site-cookbooks/kosmos-akkounts/CHANGELOG.md index 5365d00..0daf4f3 100644 --- a/site-cookbooks/kosmos-akkounts/CHANGELOG.md +++ b/site-cookbooks/kosmos-akkounts/CHANGELOG.md @@ -1,5 +1,9 @@ # kosmos-akkounts CHANGELOG +# 0.4.0 + +- Add Redis password support to the remoteStorage Redis URL. + # 0.1.0 Initial release. diff --git a/site-cookbooks/kosmos-akkounts/metadata.rb b/site-cookbooks/kosmos-akkounts/metadata.rb index 18ed462..6ea2610 100644 --- a/site-cookbooks/kosmos-akkounts/metadata.rb +++ b/site-cookbooks/kosmos-akkounts/metadata.rb @@ -4,7 +4,7 @@ maintainer_email 'mail@kosmos.org' license 'MIT' description 'Installs/configures kosmos-akkounts' long_description 'Installs/configures kosmos-akkounts' -version '0.3.0' +version '0.4.0' chef_version '>= 18.0' depends 'kosmos_openresty' diff --git a/site-cookbooks/kosmos-akkounts/recipes/default.rb b/site-cookbooks/kosmos-akkounts/recipes/default.rb index 6d04488..c673d9e 100644 --- a/site-cookbooks/kosmos-akkounts/recipes/default.rb +++ b/site-cookbooks/kosmos-akkounts/recipes/default.rb @@ -3,6 +3,7 @@ # Recipe:: default # require 'ipaddr' +require 'uri' app_name = "akkounts" deploy_user = "deploy" @@ -10,6 +11,7 @@ deploy_group = "deploy" deploy_path = "/opt/#{app_name}" credentials = Chef::EncryptedDataBagItem.load('credentials', app_name) smtp_credentials = Chef::EncryptedDataBagItem.load('credentials', 'smtp') +redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis') group deploy_group @@ -210,7 +212,8 @@ rs_redis_host = search(:node, "role:redis_server").first["knife_zero"]["host"] r rs_redis_port = node['liquor-cabinet']['redis_port'] rs_redis_db = node['liquor-cabinet']['redis_db'] if rs_redis_host - env[:rs_redis_url] = "redis://#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}" + rs_redis_password = URI.encode_www_form_component(redis_credentials['password']) + env[:rs_redis_url] = "redis://:#{rs_redis_password}@#{rs_redis_host}:#{rs_redis_port}/#{rs_redis_db}" end # diff --git a/site-cookbooks/liquor_cabinet/CHANGELOG.md b/site-cookbooks/liquor_cabinet/CHANGELOG.md index feaf621..8191071 100644 --- a/site-cookbooks/liquor_cabinet/CHANGELOG.md +++ b/site-cookbooks/liquor_cabinet/CHANGELOG.md @@ -2,6 +2,10 @@ This file is used to list changes made in each version of the liquor_cabinet cookbook. +## 0.2.0 + +- Add Redis password support. + ## 0.1.0 Initial release. diff --git a/site-cookbooks/liquor_cabinet/metadata.rb b/site-cookbooks/liquor_cabinet/metadata.rb index bd24a4c..20eecaa 100644 --- a/site-cookbooks/liquor_cabinet/metadata.rb +++ b/site-cookbooks/liquor_cabinet/metadata.rb @@ -3,7 +3,7 @@ maintainer 'Kosmos Developers' maintainer_email 'ops@kosmos.org' license 'MIT' description 'Installs/configures the Liquor Cabinet remoteStorage API server' -version '0.1.0' +version '0.2.0' chef_version '>= 18.2' issues_url 'https://gitea.kosmos.org/kosmos/chef/issues' # source_url 'https://gitea.kosmos.org/kosmos/chef' diff --git a/site-cookbooks/liquor_cabinet/recipes/default.rb b/site-cookbooks/liquor_cabinet/recipes/default.rb index 39687cd..f333f69 100644 --- a/site-cookbooks/liquor_cabinet/recipes/default.rb +++ b/site-cookbooks/liquor_cabinet/recipes/default.rb @@ -8,6 +8,7 @@ deploy_user = node[app_name]['user'] deploy_group = node[app_name]['group'] deploy_path = node[app_name]['deploy_path'] credentials = Chef::EncryptedDataBagItem.load('credentials', app_name) +redis_credentials = Chef::EncryptedDataBagItem.load('credentials', 'redis') ruby_version = node[app_name]['ruby']['version'] ruby_path = "/opt/ruby_build/builds/#{ruby_version}" @@ -70,6 +71,7 @@ template "#{deploy_path}/config.yml.erb" do redis_host: redis_host, redis_port: node[app_name]['redis_port'], redis_db: node[app_name]['redis_db'], + redis_password: redis_credentials['password'], s3_endpoint: node[app_name]['s3_endpoint'], s3_region: node[app_name]['s3_region'], s3_bucket: node[app_name]['s3_bucket'], diff --git a/site-cookbooks/liquor_cabinet/templates/config.yml.erb b/site-cookbooks/liquor_cabinet/templates/config.yml.erb index 615d28d..810dea2 100644 --- a/site-cookbooks/liquor_cabinet/templates/config.yml.erb +++ b/site-cookbooks/liquor_cabinet/templates/config.yml.erb @@ -4,6 +4,7 @@ host: <%= @redis_host %> port: <%= @redis_port %> db: <%= @redis_db %> + password: <%= @redis_password.to_json %> s3: endpoint: <%= @s3_endpoint %> region: <%= @s3_region %>