Difference between revisions of "Enabling IAM principal access to your cluster"

From wikieduonline
Jump to navigation Jump to search
Line 5: Line 5:
  
 
  [[kubectl describe -n kube-system configmap/aws-auth]]
 
  [[kubectl describe -n kube-system configmap/aws-auth]]
 +
 +
 +
apiVersion: v1
 +
data:
 +
  mapRoles: |
 +
    - groups:
 +
      - system:bootstrappers
 +
      - system:nodes
 +
      rolearn: arn:aws:iam::111122223333:role/my-role
 +
      username: system:node:{{EC2PrivateDNSName}}
 +
    - groups:
 +
      - eks-console-dashboard-full-access-group
 +
      rolearn: arn:aws:iam::111122223333:role/my-console-viewer-role
 +
      username: my-console-viewer-role
 +
  mapUsers: |
 +
    - groups:
 +
      - [[system:masters]]
 +
      userarn: arn:aws:iam::111122223333:user/admin
 +
      username: admin
 +
    - groups:
 +
      - eks-console-dashboard-restricted-access-group     
 +
      userarn: arn:aws:iam::444455556666:user/my-user
 +
      username: my-user
  
  

Revision as of 21:57, 23 October 2023

system:masters
kubectl describe -n kube-system configmap/aws-auth


apiVersion: v1
data:
  mapRoles: |
    - groups:
      - system:bootstrappers
      - system:nodes
      rolearn: arn:aws:iam::111122223333:role/my-role
      username: system:node:Template:EC2PrivateDNSName
    - groups:
      - eks-console-dashboard-full-access-group
      rolearn: arn:aws:iam::111122223333:role/my-console-viewer-role
      username: my-console-viewer-role
  mapUsers: |
    - groups:
      - system:masters
      userarn: arn:aws:iam::111122223333:user/admin
      username: admin
    - groups:
      - eks-console-dashboard-restricted-access-group      
      userarn: arn:aws:iam::444455556666:user/my-user
      username: my-user


Activities


Related

See also

Advertising: