File tree Expand file tree Collapse file tree 2 files changed +19
-3
lines changed
test/integration/tls/serverspec Expand file tree Collapse file tree 2 files changed +19
-3
lines changed Original file line number Diff line number Diff line change 50
50
51
51
- name : create TLS key
52
52
no_log : True
53
- copy : content="{{ consul_tls_key }}" dest="{{ consul_key_file }}" owner={{consul_user}} group={{consul_group}}
53
+ copy : >
54
+ content="{{ consul_tls_key }}"
55
+ dest="{{ consul_key_file }}"
56
+ owner={{consul_user}}
57
+ group={{consul_group}}
58
+ mode=0600
54
59
when : consul_tls_key is defined
55
60
56
61
- name : create TLS cert
57
62
no_log : True
58
- copy : content="{{ consul_tls_cert }}" dest="{{ consul_cert_file }}" owner={{consul_user}} group={{consul_group}}
63
+ copy : >
64
+ content="{{ consul_tls_cert }}"
65
+ dest="{{ consul_cert_file }}"
66
+ owner={{consul_user}}
67
+ group={{consul_group}}
68
+ mode=0600
59
69
when : consul_tls_cert is defined
60
70
61
71
- name : create TLS root CA cert
62
72
no_log : True
63
- copy : content="{{ consul_tls_ca_cert }}" dest="{{ consul_ca_file }}" owner={{consul_user}} group={{consul_group}}
73
+ copy : >
74
+ content="{{ consul_tls_ca_cert }}"
75
+ dest="{{ consul_ca_file }}"
76
+ owner={{consul_user}}
77
+ group={{consul_group}}
78
+ mode=0600
64
79
when : consul_tls_ca_cert is defined
65
80
66
81
- name : set ownership
Original file line number Diff line number Diff line change 11
11
describe file ( "/opt/consul/cert/#{ file } " ) do
12
12
it { should be_file }
13
13
it { should be_owned_by ( 'consul' ) }
14
+ it { should be_mode 600 }
14
15
end
15
16
end
16
17
You can’t perform that action at this time.
0 commit comments