edgelesssys / constellation

Constellation is the first Confidential Kubernetes. Constellation shields entire Kubernetes clusters from the (cloud) infrastructure using confidential computing.
GNU Affero General Public License v3.0
929 stars 48 forks source link

terraform: add missing policies for AWS ALB #3063

Closed burgerdev closed 3 months ago

burgerdev commented 3 months ago

Context

Node role permissions are currently handcrafted to allow the set of use cases we identified so far. We did not consider the use of AWS LBC as an Ingress provisioner, though, and thus never checked whether the policies are sufficient.

Proposed change(s)

Related issue

Checklist

netlify[bot] commented 3 months ago

Deploy Preview for constellation-docs ready!

Name Link
Latest commit 8704da6f5fd891406adacb82661934a6bfa8347d
Latest deploy log https://app.netlify.com/sites/constellation-docs/deploys/6638c37b5484c90008d41318
Deploy Preview https://deploy-preview-3063--constellation-docs.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.