Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Use container's system CA trust store
Previously it was not possible to use this image in an environment with a CA that is not trusted by the Python trust store. This is because the rally-verify-wrapper.sh script unset any OS_CACERT environment variable (presumably assuming any CA cert would not necessarily be available in the container). This change makes it possible to bind mount CA certificates in the container under /usr/local/share/ca-certificates/ and have them added to the system trust store and used by Rally/Tempest. In this case, OS_CACERT is set automatically. If there are no certificates in /usr/local/share/ca-certificates/, we revert to the previous behaviour of unsetting OS_CACERT.
- Loading branch information