Support for role mapping

This commit is contained in:
Dale McDiarmid 2016-09-19 13:57:09 +01:00
parent 6470b01512
commit 77612a9d8e
4 changed files with 15 additions and 3 deletions

View file

@ -60,5 +60,3 @@
template: src=shield/users_roles.j2 dest={{conf_dir}}/shield/users_roles mode=0644 force=yes template: src=shield/users_roles.j2 dest={{conf_dir}}/shield/users_roles mode=0644 force=yes
when: manage_file_users and users_roles | length > 0 when: manage_file_users and users_roles | length > 0
#TODO: Support for mapping file

View file

@ -14,7 +14,14 @@
notify: load-native-realms notify: load-native-realms
when: (es_enable_xpack and '"shield" in es_xpack_features') and ((es_users is defined and es_users.native is defined) or (es_roles is defined and es_roles.native is defined)) when: (es_enable_xpack and '"shield" in es_xpack_features') and ((es_users is defined and es_users.native is defined) or (es_roles is defined and es_roles.native is defined))
#--------------------------------------------------------------------- #-----------------------------ROLE MAPPING ----------------------------------------
#Copy Roles files
- name: Copy role_mapping.yml File for Instance
template: src=shield/role_mapping.yml.j2 dest={{conf_dir}}/shield/role_mapping.yml owner={{ es_user }} group={{ es_group }} mode=0644 force=yes
when: es_role_mapping is defined
#------------------------------------------------------------------------------------
#Ensure shield conf directory is created #Ensure shield conf directory is created
- name: Ensure shield conf directory exists - name: Ensure shield conf directory exists

View file

@ -0,0 +1 @@
{{ es_role_mapping | to_nice_yaml }}

View file

@ -16,6 +16,12 @@
- watcher - watcher
es_api_basic_auth_username: es_admin es_api_basic_auth_username: es_admin
es_api_basic_auth_password: changeMe es_api_basic_auth_password: changeMe
es_role_mapping:
power_user:
- "cn=admins,dc=example,dc=com"
user:
- "cn=users,dc=example,dc=com"
- "cn=admins,dc=example,dc=com"
es_users: es_users:
native: native:
kibana4_server: kibana4_server: