Browse Source

Merge pull request #5774 from mgugino-upstream-stage/docker-option-fix

Fix missing docker option signature-verification
Scott Dodson 7 years ago
parent
commit
e007bc8a9b
2 changed files with 7 additions and 5 deletions
  1. 1 0
      roles/docker/defaults/main.yml
  2. 6 5
      roles/docker/tasks/package_docker.yml

+ 1 - 0
roles/docker/defaults/main.yml

@@ -1,5 +1,6 @@
 ---
 docker_cli_auth_config_path: '/root/.docker'
+openshift_docker_signature_verification: False
 
 # oreg_url is defined by user input.
 oreg_host: "{{ oreg_url.split('/')[0] if (oreg_url is defined and '.' in oreg_url.split('/')[0]) else '' }}"

+ 6 - 5
roles/docker/tasks/package_docker.yml

@@ -115,11 +115,12 @@
     dest: /etc/sysconfig/docker
     regexp: '^OPTIONS=.*$'
     line: "OPTIONS='\
-      {% if ansible_selinux.status | default(None) == 'enabled' and docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %}\
-      {% if docker_log_driver is defined  %} --log-driver {{ docker_log_driver }}{% endif %}\
-      {% if docker_log_options is defined %} {{ docker_log_options |  oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %}\
-      {% if docker_options is defined %} {{ docker_options }}{% endif %}\
-      {% if docker_disable_push_dockerhub is defined %} --confirm-def-push={{ docker_disable_push_dockerhub | bool }}{% endif %}'"
+      {% if ansible_selinux.status | default(None) == 'enabled' and docker_selinux_enabled | default(true) | bool %} --selinux-enabled {% endif %} \
+      {% if docker_log_driver is defined  %} --log-driver {{ docker_log_driver }}{% endif %} \
+      {% if docker_log_options is defined %} {{ docker_log_options |  oo_split() | oo_prepend_strings_in_list('--log-opt ') | join(' ')}}{% endif %} \
+      {% if docker_options is defined %} {{ docker_options }}{% endif %} \
+      {% if docker_disable_push_dockerhub is defined %} --confirm-def-push={{ docker_disable_push_dockerhub | bool }}{% endif %} \
+      --signature-verification={{ openshift_docker_signature_verification | bool }}'"
   when: docker_check.stat.isreg is defined and docker_check.stat.isreg
   notify:
   - restart docker