openshift-apps/coreos-koji-tagger: update keytab bits

- start passing in environment variable
- point it to the actual location of the keytab
- use the right username (handled in coreos-koji-tagger code)
This commit is contained in:
Dusty Mabe 2019-06-27 16:16:39 -04:00
parent db889f362f
commit ec2028fcf1
No known key found for this signature in database
GPG key ID: 3302DBD73952E671
2 changed files with 9 additions and 7 deletions

View file

@ -17,10 +17,12 @@
- jlebon
- mizdebsk
# Create a keytab. The default username will be like:
# coreos-koji-tagger/coreos-koji-tagger.phx2.fedoraproject.org@STG.FEDORAPROJECT.ORG
- role: openshift/keytab
app: coreos-koji-tagger
key: koji-keytab
secret_name: coreos-koji-tagger-coreos-bot-keytab
secret_name: coreos-koji-tagger-keytab
service: coreos-koji-tagger
host: "coreos-koji-tagger{{ env_suffix }}.fedoraproject.org"

View file

@ -18,8 +18,8 @@ spec:
spec:
containers:
- env:
# - name: COREOS_KOJI_TAGGER_KEYTAB_FILE
# value: /etc/coreos-koji-tagger-coreos-bot-keytab
- name: COREOS_KOJI_TAGGER_KEYTAB_FILE
value: /etc/coreos-koji-tagger-keytab/koji-keytab
- name: COREOS_KOJI_TAGGER_USE_STG
{% if env == "staging" %}
value: "true"
@ -27,17 +27,17 @@ spec:
value: "false"
{% endif %}
volumeMounts:
- name: coreos-koji-tagger-coreos-bot-keytab-volume
mountPath: /etc/coreos-koji-tagger-coreos-bot-keytab
- name: coreos-koji-tagger-keytab-volume
mountPath: /etc/coreos-koji-tagger-keytab
readOnly: true
image: ""
imagePullPolicy: IfNotPresent
name: coreos-koji-tagger
resources: {}
volumes:
- name: coreos-koji-tagger-coreos-bot-keytab-volume
- name: coreos-koji-tagger-keytab-volume
secret:
secretName: coreos-koji-tagger-coreos-bot-keytab
secretName: coreos-koji-tagger-keytab
optional: true
restartPolicy: Always
test: false