Skip to content

Provider enhancements: VMCA cert retrieval & registry credentials template - #97

Closed
tech2734 wants to merge 5 commits into
redhat-cop:v2from
tech2734:feature/provider-enhancements
Closed

tech2734 wants to merge 5 commits into
redhat-cop:v2from
tech2734:feature/provider-enhancements

Conversation

@tech2734

Copy link
Copy Markdown

Summary

This PR introduces several enhancements to the mtv_provider role and aap_seed role:

mtv_provider — VMCA root CA certificate retrieval

  • For VMware sources, the role now fetches the VMCA root CA certificate from the vCenter's /afd/vecs/ca endpoint (DER format), converts it to PEM, and stores it in the provider secret's cacert field.
  • Previously, the role only retrieved the leaf certificate via TLS handshake. vCenter does not include the CA in its TLS chain, so virt-v2v could not trust ESXi host connections during VDDK disk transfers.
  • Storing only the root CA (not leaf + CA) ensures trust for all certificates signed by the VMCA, including both vCenter and ESXi host certs.
  • Non-VMware sources fall back to the leaf certificate.

aap_seed — Registry credentials job template

  • Adds a new job template (OpenShift Virtualization Migration - Registry Credentials) for the utility_registry_credentials playbook.
  • Allows registry credential management to be launched from AAP with the target environment credential attached.
  • New defaults: aap_seed_registry_credentials_template_name and aap_seed_registry_credentials_playbook.

Testing

  • Tested end-to-end on homelab: provider creation, plan creation, and migration of testvm11 with validate_certs: true — SSL trust issue resolved.
  • Registry credentials template created successfully via aap_seed.

tech2734 and others added 5 commits September 22, 2026 13:56
get_certificate now uses get_certificate_chain: true to pull the
full chain (leaf + intermediates + CA) instead of only the leaf cert.
This fixes SSL trust failures in virt-v2v when the source vCenter
uses a VMCA-signed certificate.

Co-authored-by: Cursor <cursoragent@cursor.com>
vCenter does not include the CA certificate in its TLS handshake chain.
The previous get_certificate_chain approach only retrieved the leaf cert.

Now for VMware sources, the role fetches the CA certificate from the
vCenter VMCA endpoint (/afd/vecs/ca), converts it from DER to PEM,
and combines it with the leaf cert to build the full trust chain.
This fixes SSL trust errors during virt-v2v migration connections.

Co-authored-by: Cursor <cursoragent@cursor.com>
The provider secret cacert should contain only the root CA so it
trusts all certs signed by that CA, including ESXi host certs
that virt-v2v connects to directly during VDDK disk transfers.

Co-authored-by: Cursor <cursoragent@cursor.com>
Adds a new job template for the utility_registry_credentials playbook
so registry credential management can be launched from AAP with the
target environment credential attached.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

This branch is waiting to be deployed

1 waiting deployment
external-ci — ff74ff0f Waiting Sep 22, 2026 by tech2734 via external-approval #655
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant