2016-02-12 06:08:16 +08:00
|
|
|
---
|
2016-04-07 23:08:39 +08:00
|
|
|
- include: check-certs.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [k8s-secrets, facts]
|
2016-05-07 01:17:59 +08:00
|
|
|
- include: check-tokens.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: [k8s-secrets, facts]
|
2016-04-07 23:08:39 +08:00
|
|
|
|
2016-02-12 06:08:16 +08:00
|
|
|
- name: Make sure the certificate directory exits
|
|
|
|
file:
|
|
|
|
path={{ kube_cert_dir }}
|
|
|
|
state=directory
|
|
|
|
mode=o-rwx
|
|
|
|
group={{ kube_cert_group }}
|
|
|
|
|
|
|
|
- name: Make sure the tokens directory exits
|
|
|
|
file:
|
|
|
|
path={{ kube_token_dir }}
|
|
|
|
state=directory
|
|
|
|
mode=o-rwx
|
|
|
|
group={{ kube_cert_group }}
|
|
|
|
|
|
|
|
- name: Make sure the users directory exits
|
|
|
|
file:
|
|
|
|
path={{ kube_users_dir }}
|
|
|
|
state=directory
|
|
|
|
mode=o-rwx
|
|
|
|
group={{ kube_cert_group }}
|
|
|
|
|
|
|
|
- name: Populate users for basic auth in API
|
|
|
|
lineinfile:
|
|
|
|
dest: "{{ kube_users_dir }}/known_users.csv"
|
|
|
|
create: yes
|
|
|
|
line: '{{ item.value.pass }},{{ item.key }},{{ item.value.role }}'
|
|
|
|
backup: yes
|
|
|
|
with_dict: "{{ kube_users }}"
|
|
|
|
when: inventory_hostname in "{{ groups['kube-master'] }}"
|
|
|
|
notify: set secret_changed
|
|
|
|
|
|
|
|
- include: gen_certs.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: k8s-secrets
|
2016-02-12 06:08:16 +08:00
|
|
|
- include: gen_tokens.yml
|
2016-12-08 21:36:00 +08:00
|
|
|
tags: k8s-secrets
|