main.yml 1.4 KB

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. ---
  2. openshift_master_config_dir: "{{ openshift.common.config_base }}/master"
  3. manageiq_cluster_role:
  4. apiVersion: v1
  5. kind: ClusterRole
  6. metadata:
  7. name: management-infra-admin
  8. rules:
  9. - resources:
  10. - pods/proxy
  11. verbs:
  12. - '*'
  13. manageiq_metrics_admin_clusterrole:
  14. apiVersion: v1
  15. kind: ClusterRole
  16. metadata:
  17. name: hawkular-metrics-admin
  18. rules:
  19. - apiGroups:
  20. - ""
  21. resources:
  22. - hawkular-metrics
  23. - hawkular-alerts
  24. verbs:
  25. - '*'
  26. manage_iq_tmp_conf: /tmp/manageiq_admin.kubeconfig
  27. manage_iq_tasks:
  28. - policy add-role-to-user -n management-infra admin -z management-admin
  29. - policy add-role-to-user -n management-infra management-infra-admin -z management-admin
  30. - policy add-cluster-role-to-user cluster-reader system:serviceaccount:management-infra:management-admin
  31. - policy add-scc-to-user privileged system:serviceaccount:management-infra:management-admin
  32. - policy add-cluster-role-to-user system:image-puller system:serviceaccount:management-infra:inspector-admin
  33. - policy add-scc-to-user privileged system:serviceaccount:management-infra:inspector-admin
  34. - policy add-cluster-role-to-user self-provisioner system:serviceaccount:management-infra:management-admin
  35. - policy add-cluster-role-to-user hawkular-metrics-admin system:serviceaccount:management-infra:management-admin
  36. manage_iq_openshift_3_2_tasks:
  37. - policy add-cluster-role-to-user system:image-auditor system:serviceaccount:management-infra:management-admin