2020-12-21 05:05:52 +00:00
|
|
|
---
|
|
|
|
# Creates necessary privileges for services
|
|
|
|
- name: "Creating necessary privileges"
|
|
|
|
freeipa.ansible_freeipa.ipaprivilege:
|
|
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
|
|
name: "{{ item.privilege }}"
|
|
|
|
description: "{{ item.description }}"
|
|
|
|
loop: "{{ ipaprivileges }}"
|
|
|
|
when: ipaprivileges is defined
|
|
|
|
tags:
|
|
|
|
- rbac
|
|
|
|
|
|
|
|
- name: "Creating permissions"
|
|
|
|
freeipa.ansible_freeipa.ipaprivilege:
|
|
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
|
|
name: "{{ item.privilege }}"
|
|
|
|
permission: "{{ item.permissions }}"
|
|
|
|
action: member
|
|
|
|
loop: "{{ ipaprivileges }}"
|
|
|
|
when: ipaprivileges is defined
|
|
|
|
tags:
|
|
|
|
- rbac
|
|
|
|
|
|
|
|
- name: "Creating roles based on custom privileges"
|
|
|
|
freeipa.ansible_freeipa.iparole:
|
|
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
|
|
name: "{{ item.role }}"
|
|
|
|
privilege: "{{ item.privilege }}"
|
2021-01-15 04:28:47 +00:00
|
|
|
user: "{{ item.user|default(omit) }}"
|
2020-12-21 05:05:52 +00:00
|
|
|
loop: "{{ ipaprivileges }}"
|
|
|
|
when: ipaprivileges is defined
|
|
|
|
tags:
|
|
|
|
- rbac
|
|
|
|
|
|
|
|
- name: "Creating roles based on standard privileges"
|
|
|
|
freeipa.ansible_freeipa.iparole:
|
|
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
|
|
name: "{{ item.role }}"
|
|
|
|
privilege: "{{ item.privileges }}"
|
2021-01-15 04:28:47 +00:00
|
|
|
user: "{{ item.user|default(omit) }}"
|
2020-12-21 05:05:52 +00:00
|
|
|
loop: "{{ iparoles }}"
|
|
|
|
when: iparoles is defined
|
|
|
|
tags:
|
|
|
|
- rbac
|
2021-08-30 05:02:24 +00:00
|
|
|
...
|