diff --git a/README.md b/README.md index 6930d56..85b1c1b 100644 --- a/README.md +++ b/README.md @@ -22,7 +22,11 @@ Before you begin, ensure you have the following: - A running Kubernetes cluster. - Helm installed on your local machine. - AWS user credentials with appropriate permissions. - - The permissions should allow irsa-manager to call the necessary AWS APIs. You can find all the APIs that irsa-manager calls in the internal/aws/aws.go interfaces. + + - The permissions should allow irsa-manager to call the necessary AWS APIs. The following outlines the required permissions for self-hosted Kubernetes and EKS environments. + +
+for self-hosted ```json { @@ -48,6 +52,34 @@ Before you begin, ensure you have the following: } ``` +
+ +
+for EKS + +```json +{ + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Action": [ + "iam:CreateRole", + "iam:UpdateAssumeRolePolicy", + "iam:AttachRolePolicy", + "iam:DeleteRole", + "iam:DetachRolePolicy", + "iam:ListAttachedRolePolicies", + "sts:GetCallerIdentity" + ], + "Resource": "*" + } + ] +} +``` + +
+ ## Setup Follow these steps to set up IRSA on your cluster: