From 0ec048fb998076aa97b316e14ccb0e8519d2ed16 Mon Sep 17 00:00:00 2001
From: Jeff Cantrill <jcantril@redhat.com>
Date: Tue, 24 Jan 2017 21:32:11 -0500
Subject: openshift_logging link pull secret to serviceaccounts fix unlabel
 when undeploying

---
 roles/openshift_logging/tasks/install_logging.yaml | 22 ++++++++++++++++++++++
 roles/openshift_logging/tasks/oc_secret.yaml       |  7 +++++++
 2 files changed, 29 insertions(+)
 create mode 100644 roles/openshift_logging/tasks/oc_secret.yaml

(limited to 'roles/openshift_logging/tasks')

diff --git a/roles/openshift_logging/tasks/install_logging.yaml b/roles/openshift_logging/tasks/install_logging.yaml
index 00c79ee5e..d52429f03 100644
--- a/roles/openshift_logging/tasks/install_logging.yaml
+++ b/roles/openshift_logging/tasks/install_logging.yaml
@@ -57,6 +57,28 @@
     loop_var: file
   when: ansible_check_mode
 
+  # TODO replace task with oc_secret module that supports
+  # linking when available
+- name: Link Pull Secrets With Service Accounts
+  include: oc_secret.yaml
+  vars:
+    kubeconfig: "{{ mktemp.stdout }}/admin.kubeconfig"
+    subcommand: link
+    service_account: "{{sa_account}}"
+    secret_name: "{{openshift_logging_image_pull_secret}}"
+    add_args: "--for=pull"
+  with_items:
+    - default
+    - aggregated-logging-elasticsearch
+    - aggregated-logging-kibana
+    - aggregated-logging-fluentd
+    - aggregated-logging-curator
+  register: link_pull_secret
+  loop_control:
+    loop_var: sa_account
+  when: openshift_logging_image_pull_secret is defined
+  failed_when: link_pull_secret.rc != 0
+
 - name: Scaling up cluster
   include: start_cluster.yaml
   when: start_cluster | default(true) | bool
diff --git a/roles/openshift_logging/tasks/oc_secret.yaml b/roles/openshift_logging/tasks/oc_secret.yaml
new file mode 100644
index 000000000..de37e4f6d
--- /dev/null
+++ b/roles/openshift_logging/tasks/oc_secret.yaml
@@ -0,0 +1,7 @@
+---
+- command: >
+    {{ openshift.common.client_binary }}
+    --config={{ kubeconfig }}
+    secret {{subcommand}} {{service_account}} {{secret_name}}
+    {{add_args}}
+    -n {{openshift_logging_namespace}}
-- 
cgit v1.2.3