Skip to content

Commit 471a72d

Browse files
committed
Add safe yq variant (commented out)
Signed-off-by: Kurt Garloff <kurt@garloff.de>
1 parent 12ac002 commit 471a72d

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

04-cloud-secret.sh

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,8 @@ kubectl create namespace "$CS_NAMESPACE" || true
2121
# - We will detect a cacert in there and pass it to the helper chart
2222
if ! test -r "$CLOUDS_YAML"; then echo "clouds.yaml $CLOUDS_YAML not readable"; exit 2; fi
2323
CA=$(grep -A12 "^\s\s*$OS_CLOUD:\s*\$" $CLOUDS_YAML | grep '^\s*cacert:' | head -n1 | tr -d '"' | sed 's/^\s*cacert: *//')
24+
# This would be the safe way using yq:
25+
# CA=$(yq -y < $CLOUDS_YAML '.clouds."'$OS_CLOUD'".cacert' | head -n1); if test "$CA" = "null"; then unset CA; fi
2426
OS_CACERT="${OS_CACERT:-$CA}"
2527
# FIXME: We will provide more settings in cluster-settings.env later, hardcode it for now
2628
#if test "$CS_CCMLB=octavia-ovn"; then OCTOVN="--set octavia_ovn=true"; else unset OCTOVN; fi

0 commit comments

Comments
 (0)