summaryrefslogtreecommitdiffstats
path: root/roles/openshift_manageiq/vars
diff options
context:
space:
mode:
authorenoodle <efreiber@redhat.com>2015-11-23 17:46:27 +0200
committerenoodle <efreiber@redhat.com>2015-12-04 15:23:58 +0200
commit04ce758d35666c9f887a9bb1b44ccae1d20ee908 (patch)
treec01a87e5c9970bc70a9dacc606cf887e94f5fb3e /roles/openshift_manageiq/vars
parente3071fd15f70214fe9f13b847f2cc5443716d955 (diff)
downloadopenshift-04ce758d35666c9f887a9bb1b44ccae1d20ee908.tar.gz
openshift-04ce758d35666c9f887a9bb1b44ccae1d20ee908.tar.bz2
openshift-04ce758d35666c9f887a9bb1b44ccae1d20ee908.tar.xz
openshift-04ce758d35666c9f887a9bb1b44ccae1d20ee908.zip
ManageIQ Service Account: added role for ManageIQ service account
Signed-off-by: enoodle <efreiber@redhat.com>
Diffstat (limited to 'roles/openshift_manageiq/vars')
-rw-r--r--roles/openshift_manageiq/vars/main.yml24
1 files changed, 24 insertions, 0 deletions
diff --git a/roles/openshift_manageiq/vars/main.yml b/roles/openshift_manageiq/vars/main.yml
new file mode 100644
index 000000000..77e1c304b
--- /dev/null
+++ b/roles/openshift_manageiq/vars/main.yml
@@ -0,0 +1,24 @@
+manageiq_cluster_role:
+ apiVersion: v1
+ kind: ClusterRole
+ metadata:
+ name: management-infra-admin
+ rules:
+ - resources:
+ - pods/proxy
+ verbs:
+ - '*'
+
+manageiq_service_account:
+ apiVersion: v1
+ kind: ServiceAccount
+ metadata:
+ name: management-admin
+
+manage_iq_tmp_conf: /tmp/manageiq_admin.kubeconfig
+
+manage_iq_tasks:
+ - policy add-role-to-user -n management-infra admin -z management-admin
+ - policy add-role-to-user -n management-infra management-infra-admin -z management-admin
+ - policy add-cluster-role-to-user cluster-reader system:serviceaccount:management-infra:management-admin
+ - policy add-scc-to-user privileged system:serviceaccount:management-infra:management-admin