|
@@ -63,18 +63,22 @@
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
- setup
|
|
- setup
|
|
|
|
+ - rbac
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
- setup
|
|
- setup
|
|
|
|
+ - rbac
|
|
# Ensure a Keycloak is there (use rhbk_state=absent var to remove).
|
|
# Ensure a Keycloak is there (use rhbk_state=absent var to remove).
|
|
- include_role:
|
|
- include_role:
|
|
name: deploy-rhbk
|
|
name: deploy-rhbk
|
|
apply:
|
|
apply:
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
|
|
+ - setup
|
|
- sso
|
|
- sso
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
|
|
+ - setup
|
|
- sso
|
|
- sso
|
|
# Ensure OpenShift OAuth is using the Keycloak.
|
|
# Ensure OpenShift OAuth is using the Keycloak.
|
|
- include_role:
|
|
- include_role:
|
|
@@ -82,9 +86,11 @@
|
|
apply:
|
|
apply:
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
|
|
+ - setup
|
|
- auth
|
|
- auth
|
|
tags:
|
|
tags:
|
|
- prep
|
|
- prep
|
|
|
|
+ - setup
|
|
- auth
|
|
- auth
|
|
|
|
|
|
# TODO: enable user workload monitoring
|
|
# TODO: enable user workload monitoring
|
|
@@ -95,7 +101,6 @@
|
|
# TODO: label nodes with k8s.ovn.org/egress-assignable=
|
|
# TODO: label nodes with k8s.ovn.org/egress-assignable=
|
|
# TODO: define egress IP range somewhere (?)
|
|
# TODO: define egress IP range somewhere (?)
|
|
# TODO: create a private network (nmstate + bridges?)
|
|
# TODO: create a private network (nmstate + bridges?)
|
|
-# TODO: only add self-provisioner role to certain groups
|
|
|
|
|
|
|
|
# Some additional configuration for infra.
|
|
# Some additional configuration for infra.
|
|
- name: Ensure HAProxy on utility does not forward plaintext HTTP to OpenShift.
|
|
- name: Ensure HAProxy on utility does not forward plaintext HTTP to OpenShift.
|