Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing steps in the documentation of installing small foot print pcf installation on aws. #434

Closed
harisonde opened this issue Jul 1, 2018 · 12 comments
Labels

Comments

@harisonde
Copy link

Manually configuring Elastic Runtime for AWS doesn't have instructions or guide on configuring credHub(Configure the CredHub Server) details

To Reproduce
Steps to reproduce the behavior:

  1. Finish 'Manually Configuring AWS for PCF' and 'Manually Configuring Ops Manager on AWS' steps.

  2. Import 'Small Footprint PAS' product into 'Pivotal Cloud Foundry Operations Manager Installation Dashboard'.

  3. Follow the set up process for ERT as mentioned in the below link.
    https://docs.pivotal.io/pivotalcf/1-12/customizing/pcf-aws-manual-er-config.html#om-add

  4. Steps mentioned in the above link doesn't have instructions for completing 'credHub(Configure the CredHub Server)' details which is preventing me from finishing 'PCF Small Footprint installation on AWS'.

Expected behavior
Steps to configure 'credHub(Configure the CredHub Server)'.

Screenshots
If applicable, add screenshots to help explain your problem.

OS, Browser, and Version:

  • OS: Windows
  • Browser: Chrome
  • Version:22

Please look into the missing steps and provide an alternative solution to resolve this issue.

@cf-gitbot
Copy link
Member

We have created an issue in Pivotal Tracker to manage this. Unfortunately, the Pivotal Tracker project is private so you may be unable to view the contents of the story.

The labels on this github issue will be updated when the story is started.

@harisonde
Copy link
Author

Hi Team,

Any updates on this issue? We are working on a POC and any help on this would be helpful.

@pspinrad
Copy link
Member

pspinrad commented Jul 5, 2018

@harisonde thanks-- I'll check with @crawsible whether the Credhub config instructions in the v2.0 docs version of that topic https://docs.pivotal.io/pivotalcf/2-0/customizing/pcf-aws-manual-er-config.html#credhub
...are applicable to v1.12, in which case, we'll copy over or adapt appropriately-- good catch.

@pspinrad
Copy link
Member

pspinrad commented Jul 6, 2018

@harisonde the config instructions you linked to above are for Elastic Runtime v1.12, which did not use CredHub (although the underlying BOSH layer did use a BOSH CredHub server in that version, distinct from the runtime CredHub in later versions of Pivotal Application Service, formerly Elastic Runtime).

The PAS 2.0 docs do show how to configure the runtime CredHub server-- see https://docs.pivotal.io/pivotalcf/2-0/customizing/pcf-aws-manual-er-config.html#credhub -- maybe this is the version of the instructions you need?

@harisonde
Copy link
Author

harisonde commented Jul 9, 2018

@pspinrad thanks for looking into it. The document which you shared still has missing steps for configuring HSM provider partition and other related fields..

As I mentioned I still have an issue in configuring HSM provider partition details. I could see there are couple of issues(#405 and #394) opened by others for the same..Is it possible to look into it and provide an resolution on the same.

@pspinrad
Copy link
Member

pspinrad commented Jul 9, 2018

Thanks @harisonde -- good to know, and thanks for the helpful pointers-- I'll track down the info.

@pspinrad
Copy link
Member

pspinrad commented Jul 9, 2018

@harisonde hi again-- this topic (PCF v2.1 docs) shows and explains HSM Provider Partition and related fields, but if it's helpful, I'm wondering how discoverable it is? https://docs.pivotal.io/pivotalcf/2-1/opsguide/secure-si-creds.html#pas-config
If you're game, I'd like to discuss offline-- I'm pspinrad@ . As you've noted, you're not the only one having trouble with this, so it would be great to clear up-- thanks!

@harisonde
Copy link
Author

harisonde commented Jul 9, 2018

@pspinrad Thanks for sharing it...I had looked into it earlier and it still needs requiring you to provide HSM server and partition text details. It would be helpful to let us know how to create/configure HSM details if credhub needs to store keys in HSM.

Configuring credhub to use HSM is marked as optional step but it forces user to entrer HSM details..is it not an issue?

Let me know what do you think about these points...

@pspinrad
Copy link
Member

pspinrad commented Jul 9, 2018

@harisonde I know I'm throwing you lots of pointers, but wondering if the "Create an HSM Partition" instructions here might help, from the open-source Cloud Foundry docs: https://docs.cloudfoundry.org/credhub/hsm-config.html#initialize-and-configure

Also-- you're saying that if you aren't using an HSM, you still need to enter some dummy values into those fields, in order to avoid an install error? If so, that's definitely an issue that we'd need to document and fix.

Thanks again--

@harisonde
Copy link
Author

@pspinrad We are doing a POC and we don't want to install HSM . Even though HSM sections mentioned as optional it is forcing us to enter values for the same.

And we are not able to proceed by entering dummy values also as it is validating the entered values.

I believe this section should be made option and user can go ahead with out entering any HSM details if they don't want to use it.

@crawsible
Copy link

@harisonde None of the HSM fields are mandatory. The only thing you must do is create an encryption key, but you don't need to configure anything else -- just leave it all blank.

@harisonde
Copy link
Author

Thank you..Let me check and get back to you in case if I face an issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants