diff --git a/README.md b/README.md index 85b1c1b..bcb7336 100644 --- a/README.md +++ b/README.md @@ -92,6 +92,7 @@ Create a secret for irsa-manager to access AWS: kubectl create secret generic aws-secret -n irsa-manager-system \ --from-literal=aws-access-key-id= \ --from-literal=aws-secret-access-key= \ + --from-literal=aws-session-token= # Optional \ --from-literal=aws-region= \ --from-literal=aws-role-arn= # Optional: Set this if you want to switch roles diff --git a/charts/irsa-manager/README.md b/charts/irsa-manager/README.md index 95ec85d..fd0bb27 100644 --- a/charts/irsa-manager/README.md +++ b/charts/irsa-manager/README.md @@ -22,6 +22,7 @@ helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-n kubectl create secret generic aws-secret -n irsa-manager-system \ --from-literal=aws-access-key-id= \ --from-literal=aws-secret-access-key= \ + --from-literal=aws-session-token= # Optional \ --from-literal=aws-region= \ --from-literal=aws-role-arn= # Optional: Set this if you want to switch roles diff --git a/charts/irsa-manager/README.md.gotmpl b/charts/irsa-manager/README.md.gotmpl index f318312..b70834f 100644 --- a/charts/irsa-manager/README.md.gotmpl +++ b/charts/irsa-manager/README.md.gotmpl @@ -22,6 +22,7 @@ helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-n kubectl create secret generic aws-secret -n irsa-manager-system \ --from-literal=aws-access-key-id= \ --from-literal=aws-secret-access-key= \ + --from-literal=aws-session-token= # Optional \ --from-literal=aws-region= \ --from-literal=aws-role-arn= # Optional: Set this if you want to switch roles diff --git a/charts/irsa-manager/templates/deployment.yaml b/charts/irsa-manager/templates/deployment.yaml index a712ba7..7bf85b6 100644 --- a/charts/irsa-manager/templates/deployment.yaml +++ b/charts/irsa-manager/templates/deployment.yaml @@ -32,16 +32,25 @@ spec: secretKeyRef: key: aws-access-key-id name: aws-secret + optional: true - name: AWS_SECRET_ACCESS_KEY valueFrom: secretKeyRef: key: aws-secret-access-key name: aws-secret + optional: true + - name: AWS_SESSION_TOKEN + valueFrom: + secretKeyRef: + key: aws-session-token + name: aws-secret + optional: true - name: AWS_REGION valueFrom: secretKeyRef: key: aws-region name: aws-secret + optional: true - name: AWS_ROLE_ARN valueFrom: secretKeyRef: diff --git a/config/manager/manager.yaml b/config/manager/manager.yaml index ef0de88..f70479b 100644 --- a/config/manager/manager.yaml +++ b/config/manager/manager.yaml @@ -52,19 +52,25 @@ spec: secretKeyRef: name: aws-secret key: aws-access-key-id - # optional: true + optional: true - name: AWS_SECRET_ACCESS_KEY valueFrom: secretKeyRef: name: aws-secret key: aws-secret-access-key - # optional: true + optional: true + - name: AWS_SESSION_TOKEN + valueFrom: + secretKeyRef: + name: aws-secret + key: aws-session-token + optional: true - name: AWS_REGION valueFrom: secretKeyRef: name: aws-secret key: aws-region - # optional: true + optional: true - name: AWS_ROLE_ARN valueFrom: secretKeyRef: