From 69b64bc29abcebc9b210c5b30064ef185f170f5a Mon Sep 17 00:00:00 2001 From: kkb0318 Date: Sat, 1 Jun 2024 14:21:28 +0900 Subject: [PATCH] fix readme --- README.md | 16 +++++++------- charts/irsa-manager/README.md | 27 ++++++++++++++++++++++-- charts/irsa-manager/README.md.gotmpl | 31 ++++++++++++++++++++++++++++ 3 files changed, 64 insertions(+), 10 deletions(-) create mode 100644 charts/irsa-manager/README.md.gotmpl diff --git a/README.md b/README.md index f7d2507..129fd7e 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ -# irsa-manager +# IRSA Manager -irsa-manager allows you to easily set up IAM Roles for Service Accounts (IRSA) on non-EKS Kubernetes clusters. +IRSA Manager allows you to easily set up IAM Roles for Service Accounts (IRSA) on non-EKS Kubernetes clusters. ## Introduction @@ -23,7 +23,7 @@ Follow these steps to set up IRSA on your non-EKS cluster: Add the irsa-manager Helm repository and install irsa-manager: -``` +```console helm repo add kkb0318 https://kkb0318.github.io/irsa-manager helm repo update helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-namespace @@ -36,7 +36,7 @@ helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-n Create a secret for irsa-manager to access AWS: -``` +```console kubectl create secret generic aws-secret -n irsa-manager-system \ --from-literal=aws-access-key-id= \ --from-literal=aws-secret-access-key= \ @@ -49,7 +49,7 @@ kubectl create secret generic aws-secret -n irsa-manager-system \ Define and apply an IRSASetup custom resource according to your needs. -``` +```yaml apiVersion: irsa.kkb0318.github.io/v1alpha1 kind: IRSASetup metadata: @@ -68,7 +68,7 @@ spec: Execute the following commands on the control plane server to save the public and private keys for Kubernetes signatures: -``` +```console kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-privatekey}" | base64 --decode | sudo tee /etc/kubernetes/pki/irsa-manager.key > /dev/null kubectl get secret -n kube-system irsa-manager-key -o jsonpath="{.data.ssh-publickey}" | base64 --decode | sudo tee /etc/kubernetes/pki/irsa-manager.pub > /dev/null ``` @@ -121,7 +121,7 @@ You can set IRSA for the Kubernetes ServiceAccount. The following example shows that irsa-manager sets the `irsa1-sa` ServiceAccount in the kube-system and default namespaces with the AmazonS3FullAccess policy: -``` +```yaml apiVersion: irsa.kkb0318.github.io/v1alpha1 kind: IRSA metadata: @@ -147,7 +147,7 @@ For more details, please see the API Reference. To verify the above example and ensure the IRSA works correctly, you can check the following job. There is a Kubernetes job that will put one file into the S3 bucket, confirming that the Pod can assume the role to get S3 write permission: -``` +```bash cd validation sh s3-echoer.sh ``` diff --git a/charts/irsa-manager/README.md b/charts/irsa-manager/README.md index 8c95f0c..f96ae14 100644 --- a/charts/irsa-manager/README.md +++ b/charts/irsa-manager/README.md @@ -1,8 +1,31 @@ # irsa-manager -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.1.0](https://img.shields.io/badge/AppVersion-0.1.0-informational?style=flat-square) +[irsa-manager](https://github.com/kkb0318/irsa-manager) IRSA manager allows you to easily set up IAM Roles for Service Accounts (IRSA) on non-EKS Kubernetes clusters. -A Helm chart for Kubernetes +## Setup + +* Get Repo Info +```console +helm repo add kkb0318 https://kkb0318.github.io/irsa-manager +helm repo update +``` + +* Install Chart + +```console +helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-namespace +``` + +* Set AWS Secret for IRSA Manager + +```console +kubectl create secret generic aws-secret -n irsa-manager-system \ + --from-literal=aws-access-key-id= \ + --from-literal=aws-secret-access-key= \ + --from-literal=aws-region= \ + --from-literal=aws-role-arn= # Optional: Set this if you want to switch roles + +``` ## Values diff --git a/charts/irsa-manager/README.md.gotmpl b/charts/irsa-manager/README.md.gotmpl new file mode 100644 index 0000000..f318312 --- /dev/null +++ b/charts/irsa-manager/README.md.gotmpl @@ -0,0 +1,31 @@ +{{ template "chart.header" . }} + +[irsa-manager](https://github.com/kkb0318/irsa-manager) IRSA manager allows you to easily set up IAM Roles for Service Accounts (IRSA) on non-EKS Kubernetes clusters. + +## Setup + +* Get Repo Info +```console +helm repo add kkb0318 https://kkb0318.github.io/irsa-manager +helm repo update +``` + +* Install Chart + +```console +helm install irsa-manager kkb0318/irsa-manager -n irsa-manager-system --create-namespace +``` + +* Set AWS Secret for IRSA Manager + +```console +kubectl create secret generic aws-secret -n irsa-manager-system \ + --from-literal=aws-access-key-id= \ + --from-literal=aws-secret-access-key= \ + --from-literal=aws-region= \ + --from-literal=aws-role-arn= # Optional: Set this if you want to switch roles + +``` + +{{ template "chart.valuesSection" . }} +