Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update karpenter IAM policy #349

Merged
merged 1 commit into from
Oct 10, 2023
Merged

Update karpenter IAM policy #349

merged 1 commit into from
Oct 10, 2023

Conversation

errm
Copy link
Member

@errm errm commented Oct 9, 2023

This updates the karpenter controller IAM policy inline with the upstream documentation/cloudformation

https://github.com/aws/karpenter/blob/27ad171092b9d448f7ed8f0f6fc9754419d3c12d/website/content/en/docs/getting-started/getting-started-with-karpenter/cloudformation.yaml#L37-L212

The advantage of this policy is that more resources are scoped, so the chance of unxpected opperation impacting other resources e.g. (from another cluster) is reduced.

@errm errm requested a review from a team as a code owner October 9, 2023 15:32
@errm errm force-pushed the errm/karpenter-iam-updates branch from bdd7834 to 9a79602 Compare October 9, 2023 17:43
This updates the karpenter controller IAM policy inline with the
upstream documentation/cloudformation

https://github.com/aws/karpenter/blob/27ad171092b9d448f7ed8f0f6fc9754419d3c12d/website/content/en/docs/getting-started/getting-started-with-karpenter/cloudformation.yaml#L37-L212

The advantage of this policy is that more resources are scoped,
so the chance of unxpected opperation impacting other resources
e.g. (from another cluster) is reduced.
@errm errm force-pushed the errm/karpenter-iam-updates branch from 9a79602 to 559609d Compare October 10, 2023 09:52
@errm errm merged commit 9158e51 into main Oct 10, 2023
3 checks passed
@errm errm deleted the errm/karpenter-iam-updates branch October 10, 2023 10:36
errm added a commit that referenced this pull request Oct 10, 2023
This updates the karpenter controller IAM policy inline with the
upstream documentation/cloudformation

https://github.com/aws/karpenter/blob/27ad171092b9d448f7ed8f0f6fc9754419d3c12d/website/content/en/docs/getting-started/getting-started-with-karpenter/cloudformation.yaml#L37-L212

The advantage of this policy is that more resources are scoped,
so the chance of unxpected opperation impacting other resources
e.g. (from another cluster) is reduced.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant