|
|
|
|
@ -18,18 +18,18 @@ bootstrap:
|
|
|
|
|
clientID: "argocd"
|
|
|
|
|
clientSecret: $oidc.keycloak.clientSecret
|
|
|
|
|
requestedScopes: ["openid", "profile", "email", "groups"]
|
|
|
|
|
rbacConfig:
|
|
|
|
|
policy.default: ''
|
|
|
|
|
policy.csv: |
|
|
|
|
|
g, admin, role:admin
|
|
|
|
|
g, argocd-admins, role:admin
|
|
|
|
|
g, mobenedevs, role:mobene-users
|
|
|
|
|
p, role:mobene-users, project, get, mobene, allow
|
|
|
|
|
p, role:mobene-users, applications, get, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, applications, sync, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, repositories, get, *, allow
|
|
|
|
|
p, role:mobene-users, logs, get, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, exec, create, mobene/*, allow
|
|
|
|
|
rbac:
|
|
|
|
|
policy.default: ''
|
|
|
|
|
policy.csv: |
|
|
|
|
|
g, admin, role:admin
|
|
|
|
|
g, argocd-admins, role:admin
|
|
|
|
|
g, mobenedevs, role:mobene-users
|
|
|
|
|
p, role:mobene-users, project, get, mobene, allow
|
|
|
|
|
p, role:mobene-users, applications, get, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, applications, sync, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, repositories, get, *, allow
|
|
|
|
|
p, role:mobene-users, logs, get, mobene/*, allow
|
|
|
|
|
p, role:mobene-users, exec, create, mobene/*, allow
|
|
|
|
|
|
|
|
|
|
# grafana:
|
|
|
|
|
# grafana_ini:
|
|
|
|
|
|