-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathgitlab-admin.tf
38 lines (34 loc) · 951 Bytes
/
gitlab-admin.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
data "google_client_config" "default" {}
provider "kubernetes" {
host = "https://${module.gke.endpoint}"
cluster_ca_certificate = base64decode(module.gke.ca_certificate)
token = data.google_client_config.default.access_token
load_config_file = false
}
resource "kubernetes_service_account" "gitlab-admin" {
metadata {
name = "gitlab-admin"
namespace = "kube-system"
}
}
data "kubernetes_secret" "gitlab-admin-token" {
metadata {
name = kubernetes_service_account.gitlab-admin.default_secret_name
namespace = "kube-system"
}
}
resource "kubernetes_cluster_role_binding" "gitlab-admin" {
metadata {
name = "gitlab-admin"
}
role_ref {
api_group = "rbac.authorization.k8s.io"
kind = "ClusterRole"
name = "cluster-admin"
}
subject {
kind = "ServiceAccount"
name = "gitlab-admin"
namespace = "kube-system"
}
}