linzhengen / tech-notes

My tech notes write in github issues🧲
1 stars 0 forks source link

[20210816] EKSのRBAC認証はCognitoと連携できる!!! #135

Open linzhengen opened 3 years ago

linzhengen commented 3 years ago

Doc

https://aws.amazon.com/jp/blogs/containers/introducing-oidc-identity-provider-authentication-amazon-eks/

ClusterRoleBindingのやり方

kind: ClusterRoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  name: read-secrets-role-binding
  namespace: default
subjects:
- kind: Group
  # Cognitoのグループ名を指定
  name: "gid:secret-reader"
  apiGroup: rbac.authorization.k8s.io
roleRef:
  kind: ClusterRole
  name: read-secrets
  apiGroup: rbac.authorization.k8s.io

eksctl yamlでも定義できる

https://github.com/weaveworks/eksctl/blob/main/examples/27-oidc-provider.yaml