From 3d556a4533b6e271d8f57461cd4c3727748803be Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?c=C4=83t=C4=83lin?= Date: Sun, 17 Mar 2024 15:33:09 +0100 Subject: [PATCH] feat: add admin-user's ClusterRoleBinding which maps to the argo-workflow-admin role --- .../argo-workflows/admin-service-account.yaml | 13 +++++++++++++ k8s/services/argo/ingress-route.yaml | 1 + tofu/adguard/main.tf | 5 +++++ 3 files changed, 19 insertions(+) diff --git a/k8s/services/argo-workflows/admin-service-account.yaml b/k8s/services/argo-workflows/admin-service-account.yaml index 0de82ba..5907eb1 100644 --- a/k8s/services/argo-workflows/admin-service-account.yaml +++ b/k8s/services/argo-workflows/admin-service-account.yaml @@ -8,6 +8,19 @@ metadata: workflows.argoproj.io/rbac-rule: "true" workflows.argoproj.io/rbac-rule-precedence: "1" --- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: admin-user +subjects: + - kind: ServiceAccount + name: admin-user + namespace: argo-workflows +roleRef: + name: argo-workflows-admin + kind: ClusterRole + apiGroup: rbac.authorization.k8s.io +--- apiVersion: v1 kind: Secret metadata: diff --git a/k8s/services/argo/ingress-route.yaml b/k8s/services/argo/ingress-route.yaml index 8fd4706..7e0975b 100644 --- a/k8s/services/argo/ingress-route.yaml +++ b/k8s/services/argo/ingress-route.yaml @@ -6,6 +6,7 @@ metadata: spec: entryPoints: - websecure + - web routes: - kind: Rule match: Host(`argo.fuku`) diff --git a/tofu/adguard/main.tf b/tofu/adguard/main.tf index f4966bf..c4d8291 100644 --- a/tofu/adguard/main.tf +++ b/tofu/adguard/main.tf @@ -105,3 +105,8 @@ resource "adguard_rewrite" "ci_local_3" { domain = "ci.fuku" answer = "192.168.1.33" } + +resource "adguard_rewrite" "ace" { + domain = "ace.fuku" + answer = "192.168.1.14" +}