Open james-callahan opened 1 year ago
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
Provide feedback via https://github.com/aws-controllers-k8s/community.
/lifecycle stale
/lifecycle frozen
This is definitely a request we have seen quite a few times, and solving this is part of our wider vision for managing EKS clusters using ACK
Has there been any progress/discussion on this? @RedbackThomson ? IMO it's a pretty critical use-case for the ACK IAM controller
I was thinking about this feature as well. Is this a good idea? to manage the IRSA roles in the cluster itself. IMO each app should be the one to manage its irsa and not some external Terraform or CloudFormation code.
Can we get an official statement on this?
Is your feature request related to a problem? When using the IAM controller, I expect to be able to create an IAM role suitable for use with IRSA
This would involve creation of an
assumeRolePolicyDocument
of something like:Describe the solution you'd like
assumeRolePolicyDocument
, have an (optional) kubernetes native form. e.g.Enhance
FieldExport
to be more like kustomize replacements, supporting:delimiter
andindex
This enhancement is possibly related to https://github.com/aws-controllers-k8s/community/issues/1417
e.g.
Describe alternatives you've considered
assumeRolePolicyDocument
could be a templatable string?Role
explicitly made for this purpose that can reference anOIDCProvider