diff options
author | Changjun Wang <310397125@qq.com> | 2019-03-28 06:23:28 +0000 |
---|---|---|
committer | Changjun Wang <310397125@qq.com> | 2019-03-28 06:23:28 +0000 |
commit | b322e0914ea5210e9e71d199ed1d41b0e7adddeb (patch) | |
tree | b3dc03e02c749a1e94db938978897e87ae375111 | |
parent | 9ac3a7a4882bf8d0a0814d8cff9b4abd62a74a9f (diff) |
Add https support for multicloud lenovo
The https endpoint can be enabled by setting env: SSL_ENABLED=true
Issue-ID: MULTICLOUD-538
Change-Id: I20ca09c431380d65098d42fadd1d92003cca69ba
Signed-off-by: Changjun Wang <310397125@qq.com>
-rw-r--r-- | lenovo/assembly.xml | 2 | ||||
-rw-r--r-- | lenovo/docker/Dockerfile | 6 | ||||
-rwxr-xr-x | lenovo/run.sh | 9 | ||||
-rw-r--r-- | lenovo/thinkcloud/pub/ssl/cert/cert.crt | 22 | ||||
-rw-r--r-- | lenovo/thinkcloud/pub/ssl/cert/cert.key | 28 |
5 files changed, 63 insertions, 4 deletions
diff --git a/lenovo/assembly.xml b/lenovo/assembly.xml index d7c98d96..9bda154b 100644 --- a/lenovo/assembly.xml +++ b/lenovo/assembly.xml @@ -32,6 +32,8 @@ <include>**/*.xsd</include> <include>**/*.bpel</include> <include>**/*.yml</include> + <include>**/*.crt</include> + <include>**/*.key</include> </includes> </fileSet> <fileSet> diff --git a/lenovo/docker/Dockerfile b/lenovo/docker/Dockerfile index 9e98f3f4..09011351 100644 --- a/lenovo/docker/Dockerfile +++ b/lenovo/docker/Dockerfile @@ -35,15 +35,17 @@ RUN groupadd -r onap && useradd -r -g onap onap # COPY ./ /opt/lenovo/
RUN apt-get update && \
- apt-get install -y memcached wget unzip gcc && \
+ apt-get install -y memcached wget unzip gcc libssl-dev && \
cd /opt/ && \
wget -O multicloud-openstack-lenovo.zip "https://nexus.onap.org/service/local/artifact/maven/redirect?r=snapshots&g=org.onap.multicloud.openstack&a=multicloud-openstack-lenovo&e=zip&v=1.3.0-SNAPSHOT" && \
unzip -q -o -B multicloud-openstack-lenovo.zip && \
chmod +x /opt/lenovo/*.sh &&\
rm -f multicloud-openstack-lenovo.zip &&\
pip install -r /opt/lenovo/requirements.txt &&\
- apt-get --purge remove -y wget unzip gcc && \
+ apt-get --purge remove -y wget unzip gcc libssl-dev && \
apt-get -y autoremove && \
+ mkdir -p /var/log/onap/multicloud/openstack/lenovo && \
+ chown onap:onap /var/log/onap -R && \
chown onap:onap /opt/lenovo -R
USER onap
diff --git a/lenovo/run.sh b/lenovo/run.sh index e5da37c3..45d109f7 100755 --- a/lenovo/run.sh +++ b/lenovo/run.sh @@ -17,7 +17,12 @@ memcached -d -m 2048 -u root -c 1024 -p 11211 -P /tmp/memcached1.pid export PYTHONPATH=lib/share #nohup python manage.py runserver 0.0.0.0:9010 2>&1 & -nohup uwsgi --http :9010 --module thinkcloud.wsgi --master --processes 4 & +#nohup uwsgi --http :9010 --module thinkcloud.wsgi --master --processes 4 & +if [ ${SSL_ENABLED} = "true" ]; then + nohup uwsgi --https :9010,thinkcloud/pub/ssl/cert/cert.crt,thinkcloud/pub/ssl/cert/cert.key,HIGH -t 120 --module thinkcloud.wsgi --master --processes 4 & +else + nohup uwsgi --http :9010 -t 120 --module thinkcloud.wsgi --master --processes 4 & +fi logDir="/var/log/onap/multicloud/openstack/lenovo" if [ ! -x $logDir ]; then @@ -27,4 +32,4 @@ while [ ! -f $logDir/thinkcloud.log ]; do sleep 1 done -tail -F $logDir/thinkcloud.log
\ No newline at end of file +tail -F $logDir/thinkcloud.log diff --git a/lenovo/thinkcloud/pub/ssl/cert/cert.crt b/lenovo/thinkcloud/pub/ssl/cert/cert.crt new file mode 100644 index 00000000..de0c10d5 --- /dev/null +++ b/lenovo/thinkcloud/pub/ssl/cert/cert.crt @@ -0,0 +1,22 @@ +-----BEGIN CERTIFICATE----- +MIIDgzCCAmsCCQD9YEV2Kl0P0zANBgkqhkiG9w0BAQsFADCBijELMAkGA1UEBhMC +Q04xETAPBgNVBAgMCHNpY2h1YW5nMRAwDgYDVQQHDAdjaGVuZ2R1MQwwCgYDVQQK +DAN6dGUxDjAMBgNVBAsMBXplbmFwMTgwNgYDVQQDDC9aVEUgT3BlblBhbGV0dGUg +Um9vdCBDZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxNzAeFw0xNzAzMTcwMjA4MTRa +Fw0yNzAzMTUwMjA4MTRaMHwxCzAJBgNVBAYTAkNOMREwDwYDVQQIDAhzaWNodWFu +ZzEQMA4GA1UEBwwHY2hlbmdkdTEMMAoGA1UECgwDenRlMQ4wDAYDVQQLDAV6ZW5h +cDEVMBMGA1UEAwwMKi56dGUuY29tLmNuMRMwEQYJKoZIhvcNAQkBFgRudWxsMIIB +IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxrViVMgvwA9yYBJvGsPtD0GF +Yv0fCL4Uo7gewitKImP8D8UtV7eRXZrEDtvnB2/jg/SpCeHelzR2OWdnjsWCWLeW +ERnff6Pm+tccKMQUqJllV477L+n45xlUw2Iv4w8k1M2AyQ+hqWOz9Tp+fp8XICAw +wiqqKDEclo2/Psgf5SmptZbNmjv4moKUGLy3lkgOTXz/dw9BZcid77cyhhQt0RrI +BLz/jBigkA0fWSeZIb4nTt/24JeeKLPjMUWeAwYebiS4pckICXkTpLl8/Owsqq3B +tuf2Qk3Jag0UO5zvNbl09+o9VyQcdDwPHSrbXXVSCvOsFkxbVEqZzAH7VheKnwID +AQABMA0GCSqGSIb3DQEBCwUAA4IBAQA7lw0gXfP+kfcU9cKkNmg5CtoKV2T7Xpnt +jw1Tn0YuzxR3xQmFsfcXGCD5S540uQiwINZgk+NE2qzTJylShPnjUW6DvHnzdayy +oKJmlKasZ8NCpv9lHAu+eggAMCbV1MH1mZVJqiED0gaenQAFGRAjyL7507CW9iCX +jBEEWOITpBQXQAC8TsOTQB1cHqIHFOi0rmSoDKlnGXjmofD1u3r5PChLaz4PkvGu +6CSYkOojbNYUcL4ghbFgY+dsDReN9v7nF8TQa2Vgx5cBYqqYHlBXfT1p9PP581Q8 +nWiSumRfQCwZzXdr7iUEKM3521GYKHLXfbs/aRtWAnd1ziHBpCuf +-----END CERTIFICATE----- + diff --git a/lenovo/thinkcloud/pub/ssl/cert/cert.key b/lenovo/thinkcloud/pub/ssl/cert/cert.key new file mode 100644 index 00000000..5dec2757 --- /dev/null +++ b/lenovo/thinkcloud/pub/ssl/cert/cert.key @@ -0,0 +1,28 @@ +-----BEGIN RSA PRIVATE KEY----- +MIIEpAIBAAKCAQEAxrViVMgvwA9yYBJvGsPtD0GFYv0fCL4Uo7gewitKImP8D8Ut +V7eRXZrEDtvnB2/jg/SpCeHelzR2OWdnjsWCWLeWERnff6Pm+tccKMQUqJllV477 +L+n45xlUw2Iv4w8k1M2AyQ+hqWOz9Tp+fp8XICAwwiqqKDEclo2/Psgf5SmptZbN +mjv4moKUGLy3lkgOTXz/dw9BZcid77cyhhQt0RrIBLz/jBigkA0fWSeZIb4nTt/2 +4JeeKLPjMUWeAwYebiS4pckICXkTpLl8/Owsqq3Btuf2Qk3Jag0UO5zvNbl09+o9 +VyQcdDwPHSrbXXVSCvOsFkxbVEqZzAH7VheKnwIDAQABAoIBAAFcgsTz7ifRs0Xn +Om2jg/9Dwqcv9sN3keqhO0y3QTXFG5f8ENh2AH/0rH0xkn6hjJx9056mtoCwslKo +W7RFtCPpdhS96aMVO2LikGXTGhUhn+keqKfmYXcr3EHObWeP1f/DPKuj+MaRUU1P +zkgNzPnCXrMl2a6Wz4xUgkfq1RUb1dv9C2cKGqHWYmUVx+mtATfTk4zXM/d47PRG +gpkJP40fwfUBo0dTuPdU4NxkG4LlcaJQv23bNAqyaz1Jo9E5yu4jKeTOns0bfJCd +Qvg9C91B3i3kcw1lBhk7qiS4vsdCLUrGRisIsveYC6rLgC3b+DNsRFZtxy0GetzN +1IYe8oECgYEA+FZyUqrdM8KwdQLiEoKsTSQMKt3gZh608cYKtvwkWSiWe9zoPx0H +KosyejrDd850XKqY3xOCf888H5benivrX9MmOtCxs5A/sVoooinJ7xTA7SaR3Qx6 +VpUZh6FewaG2QuWYSUmUEIbcSRhFX+qtWAtcG+HNzxU5x/cDjf/m3V8CgYEAzNbu +F64VZ/Dl8caAj7huM9wEST4ZTOx7xJCbcz7DmAJs3/XjacpK4S1sfsPBHwrnbCIQ +gO+AXbGUTuNze6QDR3uU/rRMk+qFZsuFHmNfwkJD0LWbsGP3FlHzVaW1oC1o8IgF +A9d5PV0eDoUV9dOfdhGR/48VS1xXA0YPWETRGsECgYAxzHQEa8sL1CC6dieLerS+ +i1n9Rpz3HXU/fm0roIhRcLgsgnH4JgQH3f3zUNFdtwLSiks5gJoMsyvlUcW2hiwe +/SKPbMYVsflzwRag3ixmSw0dAT0CzLvDnQaPkiaEQb9gztWo7J5KaiDGb52JzG+S +VkTUOoWg3yrFFJ2b3hMXlQKBgQCWVT9UPb0UFaaM9OQxlme6w8SZhGvJGt4S+xY7 +VFr0WwNQswN+BqtB67Zuqng3sib6I139YsjQ+p0f8Ko2mb6WXcqRy/1PqZTSRpei +H8iNp1hh+ocSw6r5xJdTylQsBGe57/nOQfuG36pJeb8ONYwYePivmHFGZ7SsgGSO +oaLdgQKBgQDerPjMGy0QxLXj/GncsfiK+ailuYsk9xAP6qIK780Nbl4m0UcjPVbf +vlgjL28HwtPYbWJCMp9rWKFfvavgxYALpgoEBC86UXfq7FHy8daBO69Juv/3smac +XtZPL1ejc2upq+XVwvOchfNSrxeyna3IhH+R6AugHWBu50ljImPJ7g== +-----END RSA PRIVATE KEY----- + |