diff --git a/salt/filebeat/init.sls b/salt/filebeat/init.sls index ac45a50cd..83f73de4f 100644 --- a/salt/filebeat/init.sls +++ b/salt/filebeat/init.sls @@ -142,7 +142,7 @@ so-filebeat: - file: filebeatmoduleconf - file: filebeatmoduledir - x509: filebeat_crt - - x509: filebeat_key + - x509: conf_filebeat_key - x509: trusttheca {% if grains.role in ES_INCLUDED_NODES %} diff --git a/salt/logstash/init.sls b/salt/logstash/init.sls index 50abd1e5b..a7ed361d6 100644 --- a/salt/logstash/init.sls +++ b/salt/logstash/init.sls @@ -201,7 +201,6 @@ so-logstash: {% endfor %} - require: - x509: filebeat_crt - - x509: filebeat_key {% if grains['role'] == 'so-heavynode' %} - x509: trusttheca {% else %} diff --git a/salt/ssl/init.sls b/salt/ssl/init.sls index 1e63a8980..645ef0fe0 100644 --- a/salt/ssl/init.sls +++ b/salt/ssl/init.sls @@ -163,7 +163,7 @@ rediskeyperms: {% endif %} {% if grains['role'] in ['so-manager', 'so-eval', 'so-helix', 'so-managersearch', 'so-standalone', 'so-import', 'so-heavynode'] %} -filebeat_key: +etc_filebeat_key: x509.private_key_managed: - name: /etc/pki/filebeat.key - CN: {{ COMMONNAME }} @@ -205,7 +205,7 @@ filebeat_crt: cmd.run: - name: "/usr/bin/openssl pkcs8 -in /etc/pki/filebeat.key -topk8 -out /etc/pki/filebeat.p8 -nocrypt" - onchanges: - - x509: filebeat_key + - x509: etc_filebeat_key fbperms: @@ -482,7 +482,7 @@ fbcertdir: - name: /opt/so/conf/filebeat/etc/pki - makedirs: True -filebeat_key: +conf_filebeat_key: x509.private_key_managed: - name: /opt/so/conf/filebeat/etc/pki/filebeat.key - CN: {{ COMMONNAME }} @@ -527,7 +527,7 @@ filebeatpkcs: cmd.run: - name: "/usr/bin/openssl pkcs8 -in /opt/so/conf/filebeat/etc/pki/filebeat.key -topk8 -out /opt/so/conf/filebeat/etc/pki/filebeat.p8 -passout pass:" - onchanges: - - x509: filebeat_key + - x509: conf_filebeat_key filebeatkeyperms: file.managed: