|
| 1 | +data "azurerm_resource_group" "default" { |
| 2 | + name = var.resource_group_name |
| 3 | +} |
| 4 | + |
| 5 | +resource "azurerm_user_assigned_identity" "dns" { |
| 6 | + name = "${var.cluster}-dns" |
| 7 | + resource_group_name = data.azurerm_resource_group.default.name |
| 8 | + location = data.azurerm_resource_group.default.location |
| 9 | +} |
| 10 | + |
| 11 | +resource "azurerm_role_assignment" "dns-reader" { |
| 12 | + scope = data.azurerm_resource_group.default.id |
| 13 | + role_definition_name = "Reader" |
| 14 | + principal_id = azurerm_user_assigned_identity.dns.principal_id |
| 15 | +} |
| 16 | + |
| 17 | +resource "azurerm_role_assignment" "dns-zone-contributor" { |
| 18 | + scope = data.azurerm_resource_group.default.id |
| 19 | + role_definition_name = "DNS Zone Contributor" |
| 20 | + principal_id = azurerm_user_assigned_identity.dns.principal_id |
| 21 | +} |
| 22 | + |
| 23 | +resource "azurerm_federated_identity_credential" "plural-runtime" { |
| 24 | + name = "${var.cluster}-plural-runtime" |
| 25 | + resource_group_name = data.azurerm_resource_group.default.name |
| 26 | + audience = ["api://AzureADTokenExchange"] |
| 27 | + issuer = module.aks.oidc_issuer_url |
| 28 | + parent_id = azurerm_user_assigned_identity.dns.id |
| 29 | + subject = "system:serviceaccount:plural-runtime:external-dns" |
| 30 | +} |
| 31 | + |
| 32 | +resource "azurerm_federated_identity_credential" "external-dns" { |
| 33 | + name = "${var.cluster}-external-dns" |
| 34 | + resource_group_name = data.azurerm_resource_group.default.name |
| 35 | + audience = ["api://AzureADTokenExchange"] |
| 36 | + issuer = module.aks.oidc_issuer_url |
| 37 | + parent_id = azurerm_user_assigned_identity.dns.id |
| 38 | + subject = "system:serviceaccount:external-dns:external-dns" |
| 39 | +} |
| 40 | + |
| 41 | +resource "azurerm_federated_identity_credential" "cert-manager" { |
| 42 | + name = "${var.cluster}-cert-manager" |
| 43 | + resource_group_name = data.azurerm_resource_group.default.name |
| 44 | + audience = ["api://AzureADTokenExchange"] |
| 45 | + issuer = module.aks.oidc_issuer_url |
| 46 | + parent_id = azurerm_user_assigned_identity.dns.id |
| 47 | + subject = "system:serviceaccount:cert-manager:cert-manager" |
| 48 | +} |
0 commit comments