Skip to content

self-hosted/docs: Expand ref architecture documentation on eksctl wellknownpolicies #12397

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Tracked by #12714
adrienthebo opened this issue Aug 25, 2022 · 1 comment
Assignees
Labels
feature: documentation meta: stale This issue/PR is stale and will be closed soon self-hosted: reference-architecture team: delivery Issue belongs to the self-hosted team type: improvement Improves an existing feature or existing code

Comments

@adrienthebo
Copy link
Contributor

Is your feature request related to a problem? Please describe

The reference architecture documentation relies on eksctl's wellKnownPolicies to grant Kubernetes service accounts cert-manager and external-dns (pending #12395) access to Route53. Because this credential is implicitly attached to a service account in the background it can be difficult to determine if the credentials were correctly attached. Complicating matters is the fact that eksctl get iamserviceaccounts seems to mis-report which wellKnownPolicies are attached to a service account.

Describe the behaviour you'd like

The reference architectures should provide verification instructions indicating how to check that AWS credentials are correctly attached to the cert-manager and external-dns service accounts.

@stale
Copy link

stale bot commented Dec 3, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the meta: stale This issue/PR is stale and will be closed soon label Dec 3, 2022
@stale stale bot closed this as completed Dec 23, 2022
Repository owner moved this from 📓Scheduled to ✨Done in 🚚 Security, Infrastructure, and Delivery Team (SID) Dec 23, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature: documentation meta: stale This issue/PR is stale and will be closed soon self-hosted: reference-architecture team: delivery Issue belongs to the self-hosted team type: improvement Improves an existing feature or existing code
Projects
No open projects
Development

No branches or pull requests

1 participant