Skip to content

Commit a349f33

Browse files
committed
argocd: use built in role:admin for admin permissions
1 parent 6362157 commit a349f33

File tree

4 files changed

+14
-11
lines changed

4 files changed

+14
-11
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,6 @@ done
2626
Create a new argocd local user for the admin (`argocd/users.yaml`).
2727
An existing admin will need to generate a password for the new admin.
2828

29-
Add the new user to the default argo project (`argocd/projects/default.yaml`).
29+
Add the new user to the admin group (`argocd/argo-cd-rbac.yaml`).
3030

3131
Have the new user create a password for accessing metrics and hash it with `htpasswd -n -B adminusername`. Add it to `monitoring/user-auth.env.yaml`.

argocd/argo-cd-rbac.yaml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
kind: ConfigMap
3+
metadata:
4+
name: argocd-rbac-cm
5+
data:
6+
policy.default: role:readonly
7+
policy.csv: |
8+
g, benharri, role:admin
9+
g, daurnimator, role:admin
10+
g, drgrove, role:admin
11+
g, lrvick, role:admin
12+
g, ryan, role:admin

argocd/kustomization.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ patches:
2626
- argo-cd-allow-alpha-plugins-patch.yaml
2727
- argo-cd-import-pgp-key.yaml
2828
- argo-cd-repository-credentials-patch.yaml
29+
- argo-cd-rbac.yaml
2930
- users.yaml
3031
images:
3132
- name: argoproj/argocd:v1.5.7

argocd/projects/default.yaml

Lines changed: 0 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -15,13 +15,3 @@ spec:
1515
kind: '*'
1616
orphanedResources:
1717
warn: false
18-
roles:
19-
- groups:
20-
- benharri
21-
- daurnimator
22-
- drgrove
23-
- lrvick
24-
- ryan
25-
name: Admins
26-
policies:
27-
- p, proj:default:Admins, applications, *, default/*, allow

0 commit comments

Comments
 (0)