Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

iam-role-for-service-accounts-eks has invalid policy for new aws accounts when attach_load_balancer_controller_policy = true #339

Closed
Apollorion opened this issue Feb 10, 2023 · 8 comments · Fixed by #358

Comments

@Apollorion
Copy link

The following two issues are also effecting the policy stored in terraform on this repo

kubernetes-sigs/aws-load-balancer-controller#2692
kubernetes-sigs/aws-load-balancer-controller#3046

Basically, the 2 condition's here are wrong.

@Apollorion Apollorion changed the title iam-role-for-service-accounts-eks has invalid policy for new aws accounts when ttach_load_balancer_controller_policy = true iam-role-for-service-accounts-eks has invalid policy for new aws accounts when attach_load_balancer_controller_policy = true Feb 10, 2023
@bryantbiggs
Copy link
Member

I am sorry but I am not following - can you please provide the information requested in the issue template

@Apollorion
Copy link
Author

Apollorion commented Feb 10, 2023

kubernetes-sigs/aws-load-balancer-controller#3046

They are updating the documented load balancer controller iam policy, which this repo replicates (its even linked here). Im just doing you a courtesy of letting you know. You guys need to update your policy in modules/iam-role-for-service-accounts-eks/policies.tf to match the recommendation of the upstream policy.

To be clear, that PR isnt merged yet, so it could change. But its current state is incorrect (as well as the one hosted in this repository). So it will change, its just a matter of when.

@bryantbiggs
Copy link
Member

ahhh, ok! Now that makes sense - got it! Thank you, I've subscribed to those linked issue/PR

@Apollorion
Copy link
Author

Just a heads up, they've merged the policy change kubernetes-sigs/aws-load-balancer-controller#3046

@github-actions
Copy link

This issue has been automatically marked as stale because it has been open 30 days
with no activity. Remove stale label or comment or this issue will be closed in 10 days

@michelzanini
Copy link
Contributor

Hi, they have merged the permissions and I have a PR to update them here. Please have a look. Thanks.

@antonbabenko
Copy link
Member

This issue has been resolved in version 5.16.0 🎉

@github-actions
Copy link

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Apr 27, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
4 participants