openshift-apps/coreos-koji-tagger: update keytab bits

- start passing in environment variable
- point it to the actual location of the keytab
- use the right username (handled in coreos-koji-tagger code)
This commit is contained in:
Dusty Mabe 2019-06-27 16:16:39 -04:00
parent db889f362f
commit ec2028fcf1
No known key found for this signature in database
GPG key ID: 3302DBD73952E671
2 changed files with 9 additions and 7 deletions

View file

@ -17,10 +17,12 @@
- jlebon - jlebon
- mizdebsk - mizdebsk
# Create a keytab. The default username will be like:
# coreos-koji-tagger/coreos-koji-tagger.phx2.fedoraproject.org@STG.FEDORAPROJECT.ORG
- role: openshift/keytab - role: openshift/keytab
app: coreos-koji-tagger app: coreos-koji-tagger
key: koji-keytab key: koji-keytab
secret_name: coreos-koji-tagger-coreos-bot-keytab secret_name: coreos-koji-tagger-keytab
service: coreos-koji-tagger service: coreos-koji-tagger
host: "coreos-koji-tagger{{ env_suffix }}.fedoraproject.org" host: "coreos-koji-tagger{{ env_suffix }}.fedoraproject.org"

View file

@ -18,8 +18,8 @@ spec:
spec: spec:
containers: containers:
- env: - env:
# - name: COREOS_KOJI_TAGGER_KEYTAB_FILE - name: COREOS_KOJI_TAGGER_KEYTAB_FILE
# value: /etc/coreos-koji-tagger-coreos-bot-keytab value: /etc/coreos-koji-tagger-keytab/koji-keytab
- name: COREOS_KOJI_TAGGER_USE_STG - name: COREOS_KOJI_TAGGER_USE_STG
{% if env == "staging" %} {% if env == "staging" %}
value: "true" value: "true"
@ -27,17 +27,17 @@ spec:
value: "false" value: "false"
{% endif %} {% endif %}
volumeMounts: volumeMounts:
- name: coreos-koji-tagger-coreos-bot-keytab-volume - name: coreos-koji-tagger-keytab-volume
mountPath: /etc/coreos-koji-tagger-coreos-bot-keytab mountPath: /etc/coreos-koji-tagger-keytab
readOnly: true readOnly: true
image: "" image: ""
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
name: coreos-koji-tagger name: coreos-koji-tagger
resources: {} resources: {}
volumes: volumes:
- name: coreos-koji-tagger-coreos-bot-keytab-volume - name: coreos-koji-tagger-keytab-volume
secret: secret:
secretName: coreos-koji-tagger-coreos-bot-keytab secretName: coreos-koji-tagger-keytab
optional: true optional: true
restartPolicy: Always restartPolicy: Always
test: false test: false