Skip to content

[aws-eks] Use only Service Linked Role for EKS clusters #7634

@pahud

Description

@pahud

❓ General Issue

Amazon EKS now supports service link roles
https://aws.amazon.com/about-aws/whats-new/2020/04/amazon-eks-supports-service-linked-roles/?nc1=h_ls

According to the eks user guide

Prior to April 16, 2020, AmazonEKSServicePolicy was also required and the suggested name was eksServiceRole. With the AWSServiceRoleForAmazonEKS service-linked role, that policy is no longer required.

eksctl just released 0.18.0 and removed the AmazonEKSServicePolicy from the cluster role.

eksctl-io/eksctl#2079

I was wondering if it's safe just remove this policy from the cluster role?

iam.ManagedPolicy.fromAwsManagedPolicyName('AmazonEKSServicePolicy'),

The Question

Environment

  • CDK CLI Version: 1.35.0
  • Module Version: aws-eks
  • OS: mac os x
  • Language: all

Other information

Metadata

Metadata

Assignees

Labels

@aws-cdk/aws-eksRelated to Amazon Elastic Kubernetes Servicefeature-requestA feature should be added or improved.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions