summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorjkaurredhat <jkaur@redhat.com>2017-07-13 14:40:05 +0530
committerjkaurredhat <jkaur@redhat.com>2017-07-13 14:40:05 +0530
commit61fbb6b57e41651beef6f226ae59683880c113c9 (patch)
treef9e1761be972c6b7df98ad89175534cf10bef369
parent12654fbe2ff56e7ba9eab61554f86a4164052a18 (diff)
downloadopenshift-61fbb6b57e41651beef6f226ae59683880c113c9.tar.gz
openshift-61fbb6b57e41651beef6f226ae59683880c113c9.tar.bz2
openshift-61fbb6b57e41651beef6f226ae59683880c113c9.tar.xz
openshift-61fbb6b57e41651beef6f226ae59683880c113c9.zip
Redeploy-certificates will fail for registry and router if user is not system:admin
Signed-off-by: jkaurredhat <jkaur@redhat.com>
-rw-r--r--playbooks/common/openshift-cluster/redeploy-certificates/registry.yml1
-rw-r--r--playbooks/common/openshift-cluster/redeploy-certificates/router.yml1
2 files changed, 2 insertions, 0 deletions
diff --git a/playbooks/common/openshift-cluster/redeploy-certificates/registry.yml b/playbooks/common/openshift-cluster/redeploy-certificates/registry.yml
index 8c8062585..afd5463b2 100644
--- a/playbooks/common/openshift-cluster/redeploy-certificates/registry.yml
+++ b/playbooks/common/openshift-cluster/redeploy-certificates/registry.yml
@@ -66,6 +66,7 @@
--signer-cert={{ openshift.common.config_base }}/master/ca.crt
--signer-key={{ openshift.common.config_base }}/master/ca.key
--signer-serial={{ openshift.common.config_base }}/master/ca.serial.txt
+ --config={{ mktemp.stdout }}/admin.kubeconfig
--hostnames="{{ docker_registry_service_ip.results.clusterip }},docker-registry.default.svc,docker-registry.default.svc.cluster.local,{{ docker_registry_route_hostname }}"
--cert={{ openshift.common.config_base }}/master/registry.crt
--key={{ openshift.common.config_base }}/master/registry.key
diff --git a/playbooks/common/openshift-cluster/redeploy-certificates/router.yml b/playbooks/common/openshift-cluster/redeploy-certificates/router.yml
index 9f14f2d69..f46553a95 100644
--- a/playbooks/common/openshift-cluster/redeploy-certificates/router.yml
+++ b/playbooks/common/openshift-cluster/redeploy-certificates/router.yml
@@ -116,6 +116,7 @@
tls.crt="{{ mktemp.stdout }}/openshift-hosted-router-certificate.pem"
tls.key="{{ mktemp.stdout }}/openshift-hosted-router-certificate.key"
--type=kubernetes.io/tls
+ --config={{ mktemp.stdout }}/admin.kubeconfig
--confirm
-o json | {{ openshift.common.client_binary }} replace -f -