From a55675acf837f22b711110dcbd3d74752081d7f8 Mon Sep 17 00:00:00 2001
From: Matthew Mosesohn <matthew.mosesohn@gmail.com>
Date: Fri, 29 Sep 2017 09:18:24 +0100
Subject: [PATCH] Enable RBAC with kubeadm always (#1711)

---
 roles/kubespray-defaults/defaults/main.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/roles/kubespray-defaults/defaults/main.yaml b/roles/kubespray-defaults/defaults/main.yaml
index 44400f16b..6e84a0311 100644
--- a/roles/kubespray-defaults/defaults/main.yaml
+++ b/roles/kubespray-defaults/defaults/main.yaml
@@ -146,7 +146,7 @@ openstack_lbaas_enabled: false
 ## the k8s cluster. Only 'AlwaysAllow','AlwaysDeny', and
 ## 'RBAC' modes are tested.
 authorization_modes: []
-rbac_enabled: "{{ 'RBAC' in authorization_modes }}"
+rbac_enabled: "{{ 'RBAC' in authorization_modes or kubeadm_enabled }}"
 
 ## List of key=value pairs that describe feature gates for
 ## the k8s cluster.
-- 
GitLab