@ -115,7 +115,7 @@ vault_pki_mounts:
roles:
- name : vault
group : vault
password : "{{ lookup('password', inventory_dir + '/credentials/vault/vault length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/vault.creds length=15') }}"
policy_rules : default
role_options : default
etcd:
@ -127,7 +127,7 @@ vault_pki_mounts:
roles:
- name : etcd
group : etcd
password : "{{ lookup('password', inventory_dir + '/credentials/vault/etcd length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/etcd.creds length=15') }}"
policy_rules : default
role_options:
allow_any_name : true
@ -142,7 +142,7 @@ vault_pki_mounts:
roles:
- name : kube-master
group : kube-master
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-master length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-master.creds length=15') }}"
policy_rules : default
role_options:
allow_any_name : true
@ -150,7 +150,7 @@ vault_pki_mounts:
organization : "system:masters"
- name : kube-node
group : k8s-cluster
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-node length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-node.creds length=15') }}"
policy_rules : default
role_options:
allow_any_name : true
@ -158,7 +158,7 @@ vault_pki_mounts:
organization : "system:nodes"
- name : kube-proxy
group : k8s-cluster
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-proxy length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-proxy.creds length=15') }}"
policy_rules : default
role_options:
allow_any_name : true
@ -166,7 +166,7 @@ vault_pki_mounts:
organization : "system:node-proxier"
- name : front-proxy-client
group : k8s-cluster
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-proxy length=15') }}"
password : "{{ lookup('password', inventory_dir + '/credentials/vault/kube-proxy.creds length=15') }}"
policy_rules : default
role_options:
allow_any_name : true