Skip to content
Snippets Groups Projects
Commit 5e8d4fef authored by OZGCloud's avatar OZGCloud
Browse files

OZG-3961 - konfiguration service account

parent d66e258a
Branches
Tags
No related merge requests found
...@@ -6,9 +6,11 @@ ...@@ -6,9 +6,11 @@
### CRDs im Cluster anlegen ### CRDs im Cluster anlegen
kubectl apply -f doc/crds/*yaml kubectl apply -f doc/crds/
### Service Account anlegen ### Service Account RBACs anlegen
kubectl apply -f doc/ServiceAccount/*yaml kubectl apply -f doc/ServiceAccount/
Hinweis: Der Service Account wird automatisch angelegt
...@@ -23,23 +23,25 @@ ...@@ -23,23 +23,25 @@
# #
--- ---
kind: ClusterRoleBinding kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: ozg-operator-secrets-viewer-role-binding name: ozg-operator-keycloak-secrets-viewer-role-binding
namespace: keycloak
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: Role
name: ozg-operator-secrets-viewer-role name: ozg-operator-keycloak-secrets-viewer-role
apiGroup: rbac.authorization.k8s.io apiGroup: rbac.authorization.k8s.io
--- ---
kind: ClusterRole kind: Role
apiVersion: rbac.authorization.k8s.io/v1 apiVersion: rbac.authorization.k8s.io/v1
metadata: metadata:
name: ozg-operator-secrets-viewer-role name: ozg-operator-keycloak-secrets-viewer-role
namespace: keycloak
rules: rules:
- apiGroups: - apiGroups:
- "*" - "*"
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakclient-viewer-role name: ozg-operator-keycloakclient-viewer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakclient-writer-role name: ozg-operator-keycloakclient-writer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakgroup-viewer-role name: ozg-operator-keycloakgroup-viewer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakgroup-writer-role name: ozg-operator-keycloakgroup-writer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakrealm-viewer-role name: ozg-operator-keycloakrealm-viewer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakrealm-writer-role name: ozg-operator-keycloakrealm-writer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakuser-viewer-role name: ozg-operator-keycloakuser-viewer-role
......
...@@ -30,7 +30,7 @@ metadata: ...@@ -30,7 +30,7 @@ metadata:
subjects: subjects:
- kind: ServiceAccount - kind: ServiceAccount
name: ozg-operator-serviceaccount name: ozg-operator-serviceaccount
namespace: by-torsten-ozg-operator-dev namespace: by-ozg-operator-dev
roleRef: roleRef:
kind: ClusterRole kind: ClusterRole
name: ozg-operator-keycloakuser-writer-role name: ozg-operator-keycloakuser-writer-role
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment