jenkins-x / terraform-aws-eks-jx

A Terraform module for creating Jenkins X infrastructure on AWS
Apache License 2.0
63 stars 43 forks source link

fix: update iam roles to jx3 naming scheme and match sa names to trust relationships #177

Closed ajpauwels closed 4 years ago

ajpauwels commented 4 years ago

Description

This PR adds jx3-conditional changes to the IAM role names for the cert-manager and external-dns IAM roles. It removes the random generated seed so the names are predictable and usable in subsequent version stream'ed charts (i.e. role ARN annotations).

Special notes for the reviewer(s)

You'll notice that the cert-manager IAM role has a "weird" name of <CLUSTER NAME>-cert-manager-cert-manager. This is because the convention across the board seems to be that the IAM roles are named according to <CLUSTER NAME>-<NAMESPACE OF THE SA IT SERVES>-<NAME OF THE SA>. I've kept this, as it also matches up nicely with the role-arn annotations in the version stream for the cert-manager and external-dns chart templates. We can change this but we'll just need to update those templates in the version stream simultaneously.

Which issue this PR fixes

fixes #175 fixes #176 fixes #178

Submitter checklist

jenkins-x-bot commented 4 years ago

Hi @ajpauwels. Thanks for your PR.

I'm waiting for a jenkins-x member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [jenkins-x/lighthouse](https://github.com/jenkins-x/lighthouse/issues/new?title=Command%20issue:) repository.
ankitm123 commented 4 years ago

/ok-to-test

ankitm123 commented 4 years ago

/lgtm

jenkins-x-bot commented 4 years ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ankitm123

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com#issuecomment-703563748/jenkins-x/terraform-aws-eks-jx/blob/master/OWNERS)~~ [ankitm123] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
ankitm123 commented 4 years ago

:tada: This PR is included in version 1.8.2 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: