Skip to content

Commit

Permalink
feat: Add elasticloadbalancing:AddTags permissions to AWS Load Bala…
Browse files Browse the repository at this point in the history
…ncer Controller policy required for version 2.4.7+ (#358)
  • Loading branch information
michelzanini authored Mar 27, 2023
1 parent 80c5a46 commit e1403c1
Showing 1 changed file with 26 additions and 0 deletions.
26 changes: 26 additions & 0 deletions modules/iam-role-for-service-accounts-eks/policies.tf
Original file line number Diff line number Diff line change
Expand Up @@ -875,6 +875,32 @@ data "aws_iam_policy_document" "load_balancer_controller" {
}
}

statement {
actions = [
"elasticloadbalancing:AddTags"
]
resources = [
"arn:${local.partition}:elasticloadbalancing:*:*:targetgroup/*/*",
"arn:${local.partition}:elasticloadbalancing:*:*:loadbalancer/net/*/*",
"arn:${local.partition}:elasticloadbalancing:*:*:loadbalancer/app/*/*",
]

condition {
test = "StringEquals"
variable = "elasticloadbalancing:CreateAction"
values = [
"CreateTargetGroup",
"CreateLoadBalancer",
]
}

condition {
test = "Null"
variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
values = ["false"]
}
}

statement {
actions = [
"elasticloadbalancing:RegisterTargets",
Expand Down

0 comments on commit e1403c1

Please sign in to comment.