mirror of
https://github.com/rocky-linux/infrastructure
synced 2024-11-11 00:11:25 +00:00
8dc0268a50
This release adds support for privileges and roles for the initial IPA team accounts.
45 lines
1.2 KiB
YAML
45 lines
1.2 KiB
YAML
---
|
|
# Creates necessary privileges for services
|
|
- name: "Creating necessary privileges"
|
|
freeipa.ansible_freeipa.ipaprivilege:
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
name: "{{ item.privilege }}"
|
|
description: "{{ item.description }}"
|
|
loop: "{{ ipaprivileges }}"
|
|
when: ipaprivileges is defined
|
|
tags:
|
|
- rbac
|
|
|
|
- name: "Creating permissions"
|
|
freeipa.ansible_freeipa.ipaprivilege:
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
name: "{{ item.privilege }}"
|
|
permission: "{{ item.permissions }}"
|
|
action: member
|
|
loop: "{{ ipaprivileges }}"
|
|
when: ipaprivileges is defined
|
|
tags:
|
|
- rbac
|
|
|
|
- name: "Creating roles based on custom privileges"
|
|
freeipa.ansible_freeipa.iparole:
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
name: "{{ item.role }}"
|
|
privilege: "{{ item.privilege }}"
|
|
user: "{{ item.user }}"
|
|
loop: "{{ ipaprivileges }}"
|
|
when: ipaprivileges is defined
|
|
tags:
|
|
- rbac
|
|
|
|
- name: "Creating roles based on standard privileges"
|
|
freeipa.ansible_freeipa.iparole:
|
|
ipaadmin_password: "{{ ipaadmin_password }}"
|
|
name: "{{ item.role }}"
|
|
privilege: "{{ item.privileges }}"
|
|
user: "{{ item.user }}"
|
|
loop: "{{ iparoles }}"
|
|
when: iparoles is defined
|
|
tags:
|
|
- rbac
|