main.yml 1.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. ---
  2. manageiq_cluster_role:
  3. apiVersion: v1
  4. kind: ClusterRole
  5. metadata:
  6. name: management-infra-admin
  7. rules:
  8. - resources:
  9. - pods/proxy
  10. verbs:
  11. - '*'
  12. manageiq_metrics_admin_clusterrole:
  13. apiVersion: v1
  14. kind: ClusterRole
  15. metadata:
  16. name: hawkular-metrics-admin
  17. rules:
  18. - apiGroups:
  19. - ""
  20. resources:
  21. - hawkular-metrics
  22. - hawkular-alerts
  23. verbs:
  24. - '*'
  25. manageiq_service_account:
  26. apiVersion: v1
  27. kind: ServiceAccount
  28. metadata:
  29. name: management-admin
  30. manageiq_image_inspector_service_account:
  31. apiVersion: v1
  32. kind: ServiceAccount
  33. metadata:
  34. name: inspector-admin
  35. manage_iq_tmp_conf: /tmp/manageiq_admin.kubeconfig
  36. manage_iq_tasks:
  37. - policy add-role-to-user -n management-infra admin -z management-admin
  38. - policy add-role-to-user -n management-infra management-infra-admin -z management-admin
  39. - policy add-cluster-role-to-user cluster-reader system:serviceaccount:management-infra:management-admin
  40. - policy add-scc-to-user privileged system:serviceaccount:management-infra:management-admin
  41. - policy add-cluster-role-to-user system:image-puller system:serviceaccount:management-infra:inspector-admin
  42. - policy add-scc-to-user privileged system:serviceaccount:management-infra:inspector-admin
  43. - policy add-cluster-role-to-user self-provisioner system:serviceaccount:management-infra:management-admin
  44. - policy add-cluster-role-to-user hawkular-metrics-admin system:serviceaccount:management-infra:management-admin
  45. manage_iq_openshift_3_2_tasks:
  46. - policy add-cluster-role-to-user system:image-auditor system:serviceaccount:management-infra:management-admin