mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
fix readme
This commit is contained in:
@@ -29,6 +29,9 @@ helm repo update
|
|||||||
helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-namespace
|
helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-namespace
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> You may encounter an error during the deployment. Proceed with the following steps and create the "aws-secret" secret to eliminate the error.
|
||||||
|
|
||||||
2. Set AWS Secret for IRSA Manager
|
2. Set AWS Secret for IRSA Manager
|
||||||
|
|
||||||
Create a secret for irsa-manager to access AWS:
|
Create a secret for irsa-manager to access AWS:
|
||||||
@@ -46,6 +49,21 @@ kubectl create secret generic aws-secret -n irsa-manager-system \
|
|||||||
|
|
||||||
Define and apply an IRSASetup custom resource according to your needs.
|
Define and apply an IRSASetup custom resource according to your needs.
|
||||||
|
|
||||||
|
```
|
||||||
|
apiVersion: irsa.kkb0318.github.io/v1alpha1
|
||||||
|
kind: IRSASetup
|
||||||
|
metadata:
|
||||||
|
name: irsa-init
|
||||||
|
namespace: irsa-manager-system
|
||||||
|
spec:
|
||||||
|
cleanup: false
|
||||||
|
mode: selfhosted
|
||||||
|
discovery:
|
||||||
|
s3:
|
||||||
|
region: <region>
|
||||||
|
bucketName: <S3 bucket name>
|
||||||
|
```
|
||||||
|
|
||||||
4. Modify kube-apiserver Settings
|
4. Modify kube-apiserver Settings
|
||||||
|
|
||||||
Execute the following commands on the control plane server to save the public and private keys for Kubernetes signatures:
|
Execute the following commands on the control plane server to save the public and private keys for Kubernetes signatures:
|
||||||
@@ -66,7 +84,7 @@ Then, modify the kube-apiserver.yaml file to include the following parameters:
|
|||||||
- Service Account Issuer
|
- Service Account Issuer
|
||||||
|
|
||||||
```
|
```
|
||||||
--service-account-issuer=https://s3-<region>.amazonaws.com/<bucketName>
|
--service-account-issuer=https://s3-<region>.amazonaws.com/<S3 bucket name>
|
||||||
```
|
```
|
||||||
|
|
||||||
- Service Account Key File
|
- Service Account Key File
|
||||||
@@ -89,25 +107,68 @@ The private key (oidc-issuer.key) generated previously can be read by the API se
|
|||||||
```
|
```
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> Add these settings before the existing ones. If specified multiple times, tokens signed by any of the specified keys are considered valid by the Kubernetes API server.
|
> Overwrite the existing settings.
|
||||||
|
|
||||||
For more details, refer to the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection).
|
For more details, refer to the [Kubernetes documentation](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#serviceaccount-token-volume-projection).
|
||||||
|
|
||||||
TODO
|
5. Check the status
|
||||||
|
|
||||||
- [x] delete secret
|
Check the IRSASetup custom resource status. If the status is true, you are ready to use IRSA.
|
||||||
- [x] delete s3
|
|
||||||
- [x] only once secret creation (status check)
|
|
||||||
- [x] no update secret
|
|
||||||
- [x] no update bucket object
|
|
||||||
- [x] delete idp
|
|
||||||
- [x] issue: when irsasetup was deleted, resource remained with some error occured
|
|
||||||
- [x] certificate
|
|
||||||
- [x] check keys.json keyid has to be empty or not
|
|
||||||
- [x] IRSA api
|
|
||||||
- [ ] use with cert-manager
|
|
||||||
- [ ] aws context
|
|
||||||
- [ ] temporary aws account
|
|
||||||
- [ ] cannot delete IRSASetup before existing IRSA
|
|
||||||
|
|
||||||
- [ ] validation webhook (invalid to change)
|
## How To Use
|
||||||
|
|
||||||
|
You can set IRSA for the Kubernetes ServiceAccount.
|
||||||
|
|
||||||
|
The following example shows that irsa-manager sets the `irsa1-sa` ServiceAccount in the kube-system and default namespaces with the AmazonS3FullAccess policy:
|
||||||
|
|
||||||
|
```
|
||||||
|
apiVersion: irsa.kkb0318.github.io/v1alpha1
|
||||||
|
kind: IRSA
|
||||||
|
metadata:
|
||||||
|
name: irsa-sample
|
||||||
|
namespace: irsa-manager-system
|
||||||
|
spec:
|
||||||
|
cleanup: true
|
||||||
|
serviceAccount:
|
||||||
|
name: irsa1-sa
|
||||||
|
namespaces:
|
||||||
|
- kube-system
|
||||||
|
- default
|
||||||
|
iamRole:
|
||||||
|
name: irsa1-role
|
||||||
|
iamPolicies:
|
||||||
|
- AmazonS3FullAccess
|
||||||
|
```
|
||||||
|
|
||||||
|
For more details, please see the API Reference.
|
||||||
|
|
||||||
|
## Verification
|
||||||
|
|
||||||
|
To verify the above example and ensure the IRSA works correctly, you can check the following job.
|
||||||
|
There is a Kubernetes job that will put one file into the S3 bucket, confirming that the Pod can assume the role to get S3 write permission:
|
||||||
|
|
||||||
|
```
|
||||||
|
cd validation
|
||||||
|
sh s3-echoer.sh
|
||||||
|
```
|
||||||
|
|
||||||
|
## API Reference
|
||||||
|
|
||||||
|
You can find the reference in the [Reference](./docs/api.md) file.
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
This project is licensed under the MIT License - see the [LICENSE](./LICENSE) file for details.
|
||||||
|
|
||||||
|
## Acknowledgments
|
||||||
|
|
||||||
|
In creating this OSS project, I referred to several sources and would like to express my gratitude for their valuable information and insights.
|
||||||
|
|
||||||
|
The necessity of this project was realized through discussions in the following issue:
|
||||||
|
|
||||||
|
- https://github.com/kubernetes-sigs/cluster-api-provider-aws/issues/3560
|
||||||
|
|
||||||
|
Additionally, the implementation was guided by the following repositories:
|
||||||
|
|
||||||
|
- [smalltown/aws-irsa-example](https://github.com/smalltown/aws-irsa-example)
|
||||||
|
- [aws/amazon-eks-pod-identity-webhook](https://github.com/aws/amazon-eks-pod-identity-webhook)
|
||||||
|
|||||||
@@ -77,25 +77,25 @@ spec:
|
|||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: aws-secret
|
name: aws-secret
|
||||||
key: aws-access-key-id
|
key: aws-access-key-id
|
||||||
optional: true
|
# optional: true
|
||||||
- name: AWS_SECRET_ACCESS_KEY
|
- name: AWS_SECRET_ACCESS_KEY
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: aws-secret
|
name: aws-secret
|
||||||
key: aws-secret-access-key
|
key: aws-secret-access-key
|
||||||
optional: true
|
# optional: true
|
||||||
- name: AWS_REGION
|
- name: AWS_REGION
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: aws-secret
|
name: aws-secret
|
||||||
key: aws-region
|
key: aws-region
|
||||||
optional: true
|
# optional: true
|
||||||
- name: AWS_ROLE_ARN
|
- name: AWS_ROLE_ARN
|
||||||
valueFrom:
|
valueFrom:
|
||||||
secretKeyRef:
|
secretKeyRef:
|
||||||
name: aws-secret
|
name: aws-secret
|
||||||
key: aws-role-arn
|
key: aws-role-arn
|
||||||
optional: true
|
# optional: true
|
||||||
name: manager
|
name: manager
|
||||||
securityContext:
|
securityContext:
|
||||||
allowPrivilegeEscalation: false
|
allowPrivilegeEscalation: false
|
||||||
|
|||||||
@@ -9,4 +9,4 @@ spec:
|
|||||||
discovery:
|
discovery:
|
||||||
s3:
|
s3:
|
||||||
region: ap-northeast-1
|
region: ap-northeast-1
|
||||||
bucketName: irsa-manager-test-kkb0010101
|
bucketName: irsa-manager-test-f4vhae
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: batch/v1
|
||||||
|
kind: Job
|
||||||
|
metadata:
|
||||||
|
name: s3-echoer
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
serviceAccountName: s3-echoer
|
||||||
|
containers:
|
||||||
|
- name: main
|
||||||
|
image: amazonlinux:2018.03
|
||||||
|
command:
|
||||||
|
- "sh"
|
||||||
|
- "-c"
|
||||||
|
- "curl -sL -o /s3-echoer https://github.com/mhausenblas/s3-echoer/releases/latest/download/s3-echoer-linux && chmod +x /s3-echoer && echo This is an in-cluster test | /s3-echoer TARGET_BUCKET"
|
||||||
|
env:
|
||||||
|
- name: AWS_DEFAULT_REGION
|
||||||
|
value: "ap-northeast-1"
|
||||||
|
- name: ENABLE_IRP
|
||||||
|
value: "true"
|
||||||
|
restartPolicy: Never
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
apiVersion: batch/v1
|
||||||
|
kind: Job
|
||||||
|
metadata:
|
||||||
|
name: s3-echoer
|
||||||
|
spec:
|
||||||
|
template:
|
||||||
|
spec:
|
||||||
|
serviceAccountName: s3-echoer
|
||||||
|
containers:
|
||||||
|
- name: main
|
||||||
|
image: amazonlinux:2023
|
||||||
|
command:
|
||||||
|
- "sh"
|
||||||
|
- "-c"
|
||||||
|
- "curl -sL -o /s3-echoer https://github.com/kkb0318/s3-echoer-arm/releases/latest/download/s3-echoer-linux-arm64 && chmod +x /s3-echoer && echo This is an in-cluster test | /s3-echoer TARGET_BUCKET"
|
||||||
|
env:
|
||||||
|
- name: AWS_DEFAULT_REGION
|
||||||
|
value: "ap-northeast-1"
|
||||||
|
- name: ENABLE_IRP
|
||||||
|
value: "true"
|
||||||
|
restartPolicy: Never
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
|
||||||
|
TARGET_BUCKET_PREFIX=s3-echoer
|
||||||
|
AWS_DEFAULT_REGION=${AWS_DEFAULT_REGION:-ap-northeast-1}
|
||||||
|
JOB_TEMPLATE=job-arm.yaml.template
|
||||||
|
|
||||||
|
# deploy s3 echoer job into k8s cluster
|
||||||
|
timestamp=$(date +%s)
|
||||||
|
TARGET_BUCKET=$ROLE_NAME-$timestamp
|
||||||
|
|
||||||
|
aws s3api create-bucket \
|
||||||
|
--bucket $TARGET_BUCKET_PREFIX \
|
||||||
|
--create-bucket-configuration LocationConstraint=$AWS_DEFAULT_REGION \
|
||||||
|
--region $AWS_DEFAULT_REGION
|
||||||
|
|
||||||
|
sed -e "s/TARGET_BUCKET/${TARGET_BUCKET_PREFIX}/g" ${JOB_TEMPLATE} > s3-echoer-job.yaml
|
||||||
|
|
||||||
|
kubectl create -f s3-echoer-job.yaml
|
||||||
|
|
||||||
|
echo "The S3 bucket is $TARGET_BUCKET_PREFIX"
|
||||||
|
|
||||||
Reference in New Issue
Block a user