-
Notifications
You must be signed in to change notification settings - Fork 4
/
Copy pathaccess.yml
76 lines (66 loc) · 1.95 KB
/
access.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
---
- name: Check to see if config map already exists
k8s_facts:
kind: ConfigMap
namespace: dap
name: k8s-app-ssl
register: dapConfigMap
ignore_errors: yes
- name: Set status of configmap
set_fact:
sslConfigMap: "configured"
when: dapConfigMap.resources[0] is defined
- name: Set status of configmap
set_fact:
sslConfigMap: "unconfigured"
when: dapConfigMap.resources[0] is undefined
- name: create configmap
block:
- name: Get POD information for DAP instances
k8s_facts:
kind: pod
namespace: dap
label_selectors:
- role = source
register: dappod
until: dappod.resources[0].status.containerStatuses[0].ready == true
retries: 60
delay: 2
- name: Configure Variable with pod name
set_fact:
sourcePodName: "{{ dappod.resources[0].metadata.name }}"
- name: Get SSL cert
shell: |
kubectl exec -n dap {{ sourcePodName }} -i -- cat /opt/conjur/etc/ssl/{{dapSourceService}}.pem
register: ssl
- name: save SSL cert
local_action: copy content={{ ssl.stdout}} dest={{ playbook_dir }}/files/ssl.pem
- name: replace SSL cert config map
shell: |
kubectl -n {{ namespace }} create configmap k8s-app-ssl --from-file=ssl-certificate={{ playbook_dir }}/files/ssl.pem
with_items:
- dap
loop_control:
loop_var: namespace
- name: Delete ssl.pem file
file:
state: absent
path: "{{ playbook_dir }}/files/ssl.pem"
- name: Set status of configmap
set_fact:
sslConfigMap: "configured"
when: sslConfigMap == "unconfigured"
- name: Load DAP access manifest
k8s:
state: present
src: "{{ playbook_dir }}/files/manifests/dap/{{ manifests }}.yml"
wait: yes
wait_condition:
reason: completed
status: "True"
wait_timeout: 360
register: dapManifestStatus
with_items:
- dapAccessManifest
loop_control:
loop_var: manifests