Browse Source

Redeploy-certificates will fail for registry and router if user is not system:admin

Signed-off-by: jkaurredhat <jkaur@redhat.com>
jkaurredhat 7 years ago
parent
commit
61fbb6b57e

+ 1 - 0
playbooks/common/openshift-cluster/redeploy-certificates/registry.yml

@@ -66,6 +66,7 @@
         --signer-cert={{ openshift.common.config_base }}/master/ca.crt
         --signer-key={{ openshift.common.config_base }}/master/ca.key
         --signer-serial={{ openshift.common.config_base }}/master/ca.serial.txt
+        --config={{ mktemp.stdout }}/admin.kubeconfig
         --hostnames="{{ docker_registry_service_ip.results.clusterip }},docker-registry.default.svc,docker-registry.default.svc.cluster.local,{{ docker_registry_route_hostname }}"
         --cert={{ openshift.common.config_base }}/master/registry.crt
         --key={{ openshift.common.config_base }}/master/registry.key

+ 1 - 0
playbooks/common/openshift-cluster/redeploy-certificates/router.yml

@@ -116,6 +116,7 @@
         tls.crt="{{ mktemp.stdout }}/openshift-hosted-router-certificate.pem"
         tls.key="{{ mktemp.stdout }}/openshift-hosted-router-certificate.key"
         --type=kubernetes.io/tls
+        --config={{ mktemp.stdout }}/admin.kubeconfig
         --confirm
         -o json | {{ openshift.common.client_binary }} replace -f -