Install certmanager and sshsignhost from RPM #524
Reference in New Issue
Block a user
Delete Branch "benvin/go-signer-rpms"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
certmanager and sshsignhost are now Go binaries released as RPMs, and their packaged paths collide with the venv install these helper classes manage.
/usr/local/bin/certmanager(via generate() on the compiler); this PR removes the symlink and the RPM path is not shown → confirm RPM installs there, else point$cmdat the RPM path (same PR); a miss fails catalog compile for every node renewing certs./usr/local/bin/sshsignhost→ same fix; also confirm the Go binary accepts--valid_principals/--ttl/--public_key/--json(callers unchanged)./tmp/certmanagerin hiera, but the body says it is nested undervault:and the template renders it there → no change needed if intended; otherwise drop the key if the binary ignores it.sshca/signhost; doc/vault/README.md:92-108 still documentsssh-host-signer/hostrole→ update the doc and confirm the sshca mount/signhost role exist in terraform-vault before merge.require/ordering if the RPM owns /opt/.No findings.