kubernetes-sigs / cluster-api-provider-aws

Kubernetes Cluster API Provider AWS provides consistent deployment and day 2 operations of "self-managed" and EKS Kubernetes clusters on AWS.
http://cluster-api-aws.sigs.k8s.io/
Apache License 2.0
636 stars 561 forks source link

Document BYO security groups for EKS-managed clusters #4476

Open adammw opened 1 year ago

adammw commented 1 year ago

/kind documentation /area provider/eks

Describe the solution you'd like The Bring your own infrastructure docs describe how to set up security group overrides for self-managed clusters, but the keys used for EKS-managed clusters are not documented. Add a page under the EKS support page describing how to bring your own security groups, what the keys represent, etc.

Ankitasw commented 1 year ago

/triage accepted /priority important-soon

adammw commented 1 year ago

For whoever writes the documentation, node-eks-additional was the key we needed to use to attach the custom security group to the EKS control plane under the "Additional security groups" heading instead of one being created by CAPI. Not sure which other keys are supported, I wasn't able to influence "Cluster security group" at all as I believe that one is created by AWS.

Ankitasw commented 1 year ago

Thanks @adammw, if you have bandwidth, feel free to contribute on the same.

k8s-triage-robot commented 8 months ago

This issue is labeled with priority/important-soon but has not been updated in over 90 days, and should be re-triaged. Important-soon issues must be staffed and worked on either currently, or very soon, ideally in time for the next release.

You can:

For more details on the triage process, see https://www.kubernetes.dev/docs/guide/issue-triage/

/remove-triage accepted

k8s-triage-robot commented 5 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot commented 4 months ago

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten