Skip to content

Commit a3f2626

Browse files
committed
Add router svcacct cluster-reader role
1 parent 46d1efc commit a3f2626

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

roles/openshift_hosted/tasks/router/router.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,15 @@
3737
resource_name: hostnetwork
3838
with_items: "{{ openshift_hosted_routers }}"
3939

40+
- name: Set additional permissions for router service account
41+
oc_adm_policy_user:
42+
user: "system:serviceaccount:{{ item.namespace }}:{{ item.serviceaccount }}"
43+
namespace: "{{ item.namespace }}"
44+
resource_kind: cluster-role
45+
resource_name: cluster-reader
46+
when: item.namespace == 'default'
47+
with_items: "{{ openshift_hosted_routers }}"
48+
4049
- name: Create OpenShift router
4150
oc_adm_router:
4251
name: "{{ item.name }}"

0 commit comments

Comments
 (0)