Properly rotating BOSH_CLIENT_SECRET of client "ops_manager"
search cancel

Properly rotating BOSH_CLIENT_SECRET of client "ops_manager"

book

Article ID: 412358

calendar_today

Updated On:

Products

Operations Manager

Issue/Introduction

You may need to change credentials from Boshdirector Tile -> Credentials Tab -> Bosh Commandline Credentials.

This can be done directly in UAA, but this change will not propagate to Ops Manager web UI.

 

Resolution

In order to get it done across all the platform, follow steps 1-7 as root, from here: https://techdocs.broadcom.com/us/en/vmware-tanzu/platform/tanzu-operations-manager/3-1/tanzu-ops-manager/install-modify-ops-man.html.

Do NOT modify actual-installation.yml (step 8), since you will propagate this update to the "actual" installation with an "Apply Changes" via the UI.

When editing the decrypted installation.yml (step 4), use following command

  • sudo -u tempest-web vi /tmp/installation.yml (if you don't open impersonating tepest-web user, you won't be able to save it)

Then, update the properties for the director job. In this case the "identifier" will be "uaa_bosh_cli_client_credentials", the "password" field is the one they you would need to update. See following screenshot for clarification. 

r

After step 7 you would need to go to Step 9 and restart Operations Manager. After unlocking and logging in, you should be able to see that the secret has been updated in the manifest for the BOSH Director from the review changes page. 

Apply Changes only on the BOSH director Tile and after the BOSH director is deployed you should see in the Director credentials tab that the "Bosh Commandline Credentials" now match the new client secret configuration.