Skip to content

Commit

Permalink
Merge pull request #2877 from zalando-incubator/collaborator-pet-cluster
Browse files Browse the repository at this point in the history
Make it possible to allow collaborator admin access in pet clusters
  • Loading branch information
aermakov-zalando authored Jan 20, 2020
2 parents abb387c + 635efd7 commit dca023e
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 1 deletion.
7 changes: 7 additions & 0 deletions cluster/config-defaults.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -262,6 +262,13 @@ custom_dns_zone_nameservers: "" # space seperated list of nameserver IP addresse
# prefix prepended to ownership TXT records for external-dns
external_dns_ownership_prefix: ""

# special roles for test/pet clusters
{{if eq .Cluster.Environment "e2e"}}
collaborator_administrator_access: "true"
{{else}}
collaborator_administrator_access: "false"
{{end}}

# enable legacy serviceaccounts for smooth RBAC migration
enable_operator_sa: "false"
enable_default_sa: "false"
Expand Down
2 changes: 1 addition & 1 deletion cluster/node-pools/master-default/userdata.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -260,7 +260,7 @@ write_files:
- --derived-role=CollaboratorManual=Collaborator24x7,Manual
{{- else if eq .Cluster.Environment "test"}}
- --role-mapping=CollaboratorPowerUser=cn=Deployer,ou=collaborators,ou=Kubernetes,ou=apps,dc=zalando,dc=net
{{- else if eq .Cluster.Environment "e2e"}}
{{- else if eq .Cluster.ConfigItems.collaborator_administrator_access "true"}}
- --role-mapping=Administrator=cn=Contributor,ou=collaborators,ou=Kubernetes,ou=apps,dc=zalando,dc=net
{{- end}}

Expand Down

0 comments on commit dca023e

Please sign in to comment.