Skip to content

Commit 02bc3ae

Browse files
DOCSP-21717: first attempt at removing tls.secretRef.name
1 parent a8c8a9b commit 02bc3ae

8 files changed

+9
-139
lines changed

source/includes/admonitions/deprecate-secret-ref-name.rst

Lines changed: 0 additions & 25 deletions
This file was deleted.
Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1 @@
1-
You must prefix your secrets with ``<prefix>-<metadata.name>`` if both
2-
of the following items are true:
3-
4-
- You set :setting:`spec.security.certsSecretPrefix` or
5-
:setting:`spec.security.tls.secretRef.prefix`
6-
- You omit :setting:`spec.security.tls.secretRef.name`.
1+
You must prefix your secrets with ``<prefix>-<metadata.name>``.

source/includes/options-k8s-replica-set.yaml

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -435,13 +435,6 @@ inherit:
435435
file: options-k8s-shared.yaml
436436
---
437437
program: k8sRsConf
438-
name: spec.security.tls.secretRef.name
439-
inherit:
440-
name: spec.security.tls.secretRef.name
441-
program: _shared
442-
file: options-k8s-shared.yaml
443-
---
444-
program: k8sRsConf
445438
name: spec.security.tls.secretRef.prefix
446439
inherit:
447440
name: spec.security.tls.secretRef.prefix

source/includes/options-k8s-shared.yaml

Lines changed: 3 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -478,29 +478,6 @@ directive: setting
478478
optional: true
479479
description: |
480480
Provide the name of the |k8s-configmap| that stores the |certauth|.
481-
---
482-
program: _shared
483-
name: spec.security.tls.secretRef.name
484-
type: string
485-
directive: setting
486-
optional: true
487-
description: |
488-
Deprecated. See :setting:`spec.security.certsSecretPrefix`.
489-
Text to prefix to the |k8s| |k8s-secrets| that you created that
490-
contain your replica set's or sharded cluster's |tls| keys and
491-
certificates.
492-
493-
.. note::
494-
495-
If set, the value of :setting:`spec.security.tls.secretRef.name`
496-
overrides the following values:
497-
498-
- :setting:`spec.security.tls.secretRef.prefix`
499-
- :setting:`spec.security.certsSecretPrefix`
500-
501-
To learn more about naming the secrets that contain your |tls|
502-
certificates, see the topic in :ref:`secure-tls` that applies to your
503-
deployment.
504481
505482
---
506483
program: _shared
@@ -515,17 +492,10 @@ description: |
515492
516493
.. note::
517494
518-
If set, the value of :setting:`spec.security.tls.secretRef.name`
519-
overrides the value of :setting:`spec.security.tls.secretRef.prefix`.
520-
521495
If set, the value of :setting:`spec.security.tls.secretRef.prefix`
522496
overrides the value of :setting:`spec.security.certsSecretPrefix`.
523497
524-
You must prefix your secrets with ``<prefix>-<metadata.name>`` if both
525-
of the following items are true:
526-
527-
- You set :setting:`spec.security.certsSecretPrefix` or :setting:`spec.security.tls.secretRef.prefix`
528-
- You omit :setting:`spec.security.tls.secretRef.name`.
498+
You must prefix your secrets with ``<prefix>-<metadata.name>``.
529499
530500
To learn more about naming the secrets that contain your |tls|
531501
certificates, see the topic in :ref:`secure-tls` that applies to your
@@ -544,11 +514,8 @@ description: |
544514
545515
.. note::
546516
547-
If set, the value of the following settings override the value of
548-
:setting:`spec.security.certsSecretPrefix`:
549-
550-
- :setting:`spec.security.tls.secretRef.name`
551-
- :setting:`spec.security.tls.secretRef.prefix`
517+
If set, the value of the :setting:`spec.security.tls.secretRef.prefix`
518+
overrides the value of :setting:`spec.security.certsSecretPrefix`.
552519
553520
.. include:: /includes/fact-req-secret-prefix.rst
554521

source/includes/steps-deploy-k8s-opsmgr-http.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -509,8 +509,6 @@ content: |
509509
Create this database as a :ref:`replica set
510510
<deploy-replica-set>`.
511511
512-
.. include:: /includes/admonitions/deprecate-secret-ref-name.rst
513-
514512
Match the ``metadata.name`` of the resource with the
515513
:opsmgrkube:`spec.backup.opLogStores.mongodbResourceRef.name`
516514
that you specified in your |onprem| resource definition.

source/reference/k8s-operator-om-specification.txt

Lines changed: 5 additions & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -211,21 +211,10 @@ Optional |onprem| Resource Settings
211211

212212
.. note::
213213

214-
If set, the value of the following settings override the value of
215-
:opsmgrkube:`spec.applicationDatabase.security.certsSecretPrefix`:
214+
If set, the value of :opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`
215+
overrides the value of :opsmgrkube:`spec.applicationDatabase.security.certsSecretPrefix`.
216216

217-
- :opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.name`
218-
- :opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`
219-
220-
You must name your secret ``<prefix>-<metadata.name>-db-cert`` if
221-
all of the following items are true:
222-
223-
- You set
224-
:opsmgrkube:`spec.applicationDatabase.security.certsSecretPrefix`
225-
or
226-
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`.
227-
- You omit
228-
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.name`.
217+
You must name your secret ``<prefix>-<metadata.name>-db-cert``.
229218

230219
To learn how to configure your |onprem| instance to run over
231220
|https|, see :ref:`deploy-om-container`.
@@ -259,11 +248,6 @@ Optional |onprem| Resource Settings
259248

260249
.. note::
261250

262-
If set, the value of
263-
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.name`
264-
overrides the value of
265-
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`.
266-
267251
If set, the value of
268252
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`
269253
overrides the value of
@@ -272,24 +256,6 @@ Optional |onprem| Resource Settings
272256
To learn how to configure your |onprem| instance to run over
273257
|https|, see :ref:`deploy-om-container`.
274258

275-
.. opsmgrkube:: spec.applicationDatabase.security.tls.secretRef.name
276-
277-
.. include:: /includes/admonitions/deprecate-secret-ref-name.rst
278-
279-
*Type*: string
280-
281-
Name of the |k8s| |k8s-secret| you created to secure the application
282-
database resources.
283-
284-
.. note::
285-
286-
If set, the value of
287-
:opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.name`
288-
overrrides the values of the following settings:
289-
290-
- :opsmgrkube:`spec.applicationDatabase.security.tls.secretRef.prefix`
291-
- :opsmgrkube:`spec.applicationDatabase.security.certsSecretPrefix`
292-
293259
.. opsmgrkube:: spec.backup.enabled
294260

295261
*Type*: boolean
@@ -1103,14 +1069,10 @@ Optional |onprem| Resource Settings
11031069
.. note::
11041070

11051071
If set, the value of
1106-
:opsmgrkube:`spec.security.tls.secretRef.name` overrides the
1072+
:opsmgrkube:`spec.security.tls.secretRef.prefix` overrides the
11071073
value of :opsmgrkube:`spec.security.certsSecretPrefix`.
11081074

1109-
You must name your secret ``<prefix>-<metadata.name>-cert`` if both
1110-
of the following items are true:
1111-
1112-
- You set :opsmgrkube:`spec.security.certsSecretPrefix`, and
1113-
- You omit :opsmgrkube:`spec.security.tls.secretRef.name`.
1075+
You must name your secret ``<prefix>-<metadata.name>-cert``.
11141076

11151077
To learn how to configure your |onprem| instance to run over
11161078
|https|, see :ref:`deploy-om-container`.
@@ -1136,19 +1098,6 @@ Optional |onprem| Resource Settings
11361098

11371099
.. include:: /includes/admonitions/warning-concatenate-download-certs.rst
11381100

1139-
.. opsmgrkube:: spec.security.tls.secretRef.name
1140-
1141-
*Type*: string
1142-
1143-
.. include:: /includes/admonitions/deprecate-secret-ref-name.rst
1144-
1145-
Name of the |k8s| |k8s-secret| you created for your |onprem| |tls|
1146-
certificate. Used when creating an |onprem| instance which runs
1147-
over |https|.
1148-
1149-
To learn how to configure your |onprem| instance to run over
1150-
|https|, see :ref:`deploy-om-container`.
1151-
11521101
.. opsmgrkube:: spec.security.tls.enabled
11531102

11541103
.. important::
@@ -1175,10 +1124,6 @@ Optional |onprem| Resource Settings
11751124
certificate.
11761125

11771126
.. note::
1178-
If set, the value of
1179-
:opsmgrkube:`spec.security.tls.secretRef.name`
1180-
overrides the value of
1181-
:opsmgrkube:`spec.security.tls.secretRef.prefix`.
11821127

11831128
If set, the value of
11841129
:opsmgrkube:`spec.security.tls.secretRef.prefix`

source/reference/k8s-operator-specification.txt

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -213,7 +213,6 @@ cluster resource types:
213213
.. include:: /includes/option/setting-k8sRsConf-spec.security.tls.ca.rst
214214
.. include:: /includes/option/setting-k8sRsConf-spec.security.certsSecretPrefix.rst
215215
.. include:: /includes/option/setting-k8sRsConf-spec.security.tls.secretRef.prefix.rst
216-
.. include:: /includes/option/setting-k8sRsConf-spec.security.tls.secretRef.name.rst
217216
.. include:: /includes/option/setting-k8sRsConf-spec.security.tls.additionalCertificateDomains.rst
218217
.. include:: /includes/option/setting-k8sRsConf-spec.additionalMongodConfig.net.ssl.mode.rst
219218
.. include:: /includes/option/setting-k8sRsConf-spec.security.authentication.rst

source/tutorial/secure-tls.txt

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,6 @@ between:
2727
This guide instructs you on how to configure the |k8s-op-short| to use
2828
|tls| for its MongoDB instances.
2929

30-
.. include:: /includes/admonitions/deprecate-secret-ref-name.rst
31-
3230
.. _secure-tls-prerequisites:
3331

3432
General Prerequisites

0 commit comments

Comments
 (0)