mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
Update README to clarify permissions required for self-hosted Kubernetes and EKS
This commit is contained in:
@@ -22,7 +22,11 @@ Before you begin, ensure you have the following:
|
|||||||
- A running Kubernetes cluster.
|
- A running Kubernetes cluster.
|
||||||
- Helm installed on your local machine.
|
- Helm installed on your local machine.
|
||||||
- AWS user credentials with appropriate permissions.
|
- AWS user credentials with appropriate permissions.
|
||||||
- The permissions should allow irsa-manager to call the necessary AWS APIs. You can find all the APIs that irsa-manager calls in the internal/aws/aws.go interfaces.
|
|
||||||
|
- The permissions should allow irsa-manager to call the necessary AWS APIs. The following outlines the required permissions for self-hosted Kubernetes and EKS environments.
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>for self-hosted</summary>
|
||||||
|
|
||||||
```json
|
```json
|
||||||
{
|
{
|
||||||
@@ -48,6 +52,34 @@ Before you begin, ensure you have the following:
|
|||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>for EKS</summary>
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"Version": "2012-10-17",
|
||||||
|
"Statement": [
|
||||||
|
{
|
||||||
|
"Effect": "Allow",
|
||||||
|
"Action": [
|
||||||
|
"iam:CreateRole",
|
||||||
|
"iam:UpdateAssumeRolePolicy",
|
||||||
|
"iam:AttachRolePolicy",
|
||||||
|
"iam:DeleteRole",
|
||||||
|
"iam:DetachRolePolicy",
|
||||||
|
"iam:ListAttachedRolePolicies",
|
||||||
|
"sts:GetCallerIdentity"
|
||||||
|
],
|
||||||
|
"Resource": "*"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
## Setup
|
## Setup
|
||||||
|
|
||||||
Follow these steps to set up IRSA on your cluster:
|
Follow these steps to set up IRSA on your cluster:
|
||||||
|
|||||||
Reference in New Issue
Block a user