Difference between revisions of "MapRoles:"
Jump to navigation
Jump to search
↑ https://docs.aws.amazon.com/eks/latest/userguide/add-user-role.html
Line 17: | Line 17: | ||
[[inputs]] = { | [[inputs]] = { | ||
− | aws_auth_extra_roles = <<-[[EOF]] | + | [[aws_auth_extra_roles]] = <<-[[EOF]] |
[[mapUsers:]] | | [[mapUsers:]] | | ||
- userarn: arn:aws:iam::XXXXXXXXXXXX:user/your-aws-user | - userarn: arn:aws:iam::XXXXXXXXXXXX:user/your-aws-user |
Revision as of 14:57, 21 December 2023
Official example[1]:
mapRoles: | - groups: - system:bootstrappers - system:nodes rolearn: arn:aws:iam::111122223333:role/my-node-role username: system:node:{{EC2PrivateDNSName}}
mapUsers: | - userarn: arn:aws:iam::XXXXXXXXXXXX:user/your-aws-user username: your-k8s-new-user-with-master-privileges groups: - system:masters mapRoles: | - rolearn: arn:aws:iam::XXXXXXXXXXXX:role/your-aws-role username: your-new-k8s-user-with-master groups: - system:masters
inputs = { aws_auth_extra_roles = <<-EOF mapUsers: | - userarn: arn:aws:iam::XXXXXXXXXXXX:user/your-aws-user username: your-k8s-new-user-with-master-privileges groups: - system:masters EOF }
Related
See also
mapUsers:, mapRoles:, mapAccounts:
- AWS IAM Authenticator for Kubernetes:
aws-auth, kubectl edit -n kube-system configmap/aws-auth, eksctl create iamidentitymapping
,mapUsers:, mapRoles:, mapAccounts:
Advertising: