Browse Source
Add oidc-user-prefix and oidc-group-prefix args
pull/2695/head
Suzuka Asagiri
6 years ago
No known key found for this signature in database
GPG Key ID: 52D68F9ACE41C03
3 changed files with
10 additions and
0 deletions
-
inventory/sample/group_vars/k8s-cluster.yml
-
roles/kubernetes/master/defaults/main.yml
-
roles/kubernetes/master/templates/manifests/kube-apiserver.manifest.j2
|
|
@ -58,7 +58,9 @@ kube_users: |
|
|
|
## Optional settings for OIDC |
|
|
|
# kube_oidc_ca_file: {{ kube_cert_dir }}/ca.pem |
|
|
|
# kube_oidc_username_claim: sub |
|
|
|
# kube_oidc_username_prefix: oidc: |
|
|
|
# kube_oidc_groups_claim: groups |
|
|
|
# kube_oidc_groups_prefix: oidc: |
|
|
|
|
|
|
|
|
|
|
|
# Choose network plugin (cilium, calico, contiv, weave or flannel) |
|
|
|
|
|
@ -73,7 +73,9 @@ kube_oidc_auth: false |
|
|
|
## Optional settings for OIDC |
|
|
|
# kube_oidc_ca_file: {{ kube_cert_dir }}/ca.pem |
|
|
|
# kube_oidc_username_claim: sub |
|
|
|
# kube_oidc_username_prefix: oidc: |
|
|
|
# kube_oidc_groups_claim: groups |
|
|
|
# kube_oidc_groups_prefix: oidc: |
|
|
|
|
|
|
|
## Variables for custom flags |
|
|
|
apiserver_custom_flags: [] |
|
|
|
|
|
@ -73,9 +73,15 @@ spec: |
|
|
|
{% if kube_oidc_username_claim is defined %} |
|
|
|
- --oidc-username-claim={{ kube_oidc_username_claim }} |
|
|
|
{% endif %} |
|
|
|
{% if kube_oidc_username_prefix is defined %} |
|
|
|
- "--oidc-username-prefix={{ kube_oidc_username_prefix }}" |
|
|
|
{% endif %} |
|
|
|
{% if kube_oidc_groups_claim is defined %} |
|
|
|
- --oidc-groups-claim={{ kube_oidc_groups_claim }} |
|
|
|
{% endif %} |
|
|
|
{% if kube_oidc_groups_prefix is defined %} |
|
|
|
- "--oidc-groups-prefix={{ kube_oidc_groups_prefix }}" |
|
|
|
{% endif %} |
|
|
|
{% endif %} |
|
|
|
- --secure-port={{ kube_apiserver_port }} |
|
|
|
- --insecure-port={{ kube_apiserver_insecure_port }} |
|
|
|