Selaa lähdekoodia

Check and fix registry serviceaccount

Signed-off-by: Gladkov Alexey <agladkov@redhat.com>
Gladkov Alexey 7 vuotta sitten
vanhempi
commit
2fe4ea7080
1 muutettua tiedostoa jossa 15 lisäystä ja 0 poistoa
  1. 15 0
      roles/openshift_hosted/tasks/registry_service_account.yml

+ 15 - 0
roles/openshift_hosted/tasks/registry_service_account.yml

@@ -0,0 +1,15 @@
+---
+- name: create registry serviceaccount
+  oc_serviceaccount:
+    state: present
+    name: "{{ openshift_hosted_registry_serviceaccount }}"
+    namespace: "{{ openshift_hosted_registry_namespace }}"
+  changed_when: no
+
+- name: grant the system:registry role to registry serviceaccount
+  oc_adm_policy_user:
+    state: present
+    namespace: "{{ openshift_hosted_registry_namespace }}"
+    resource_kind: cluster-role
+    resource_name: system:registry
+    user: "system:serviceaccount:{{ openshift_hosted_registry_namespace }}:{{ openshift_hosted_registry_serviceaccount }}"