-
Notifications
You must be signed in to change notification settings - Fork 1.2k
fix: Restrict IAM permissions to those related to Karpenter managed resources #1332
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Changes from 11 commits
Commits
Show all changes
27 commits
Select commit
Hold shift + click to select a range
6dc4ca6
fix: Restrict `ssm:GetParameter` IAM permissions to only the AWS serv…
bryantbiggs 5680438
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 91638f7
chore: update permissions and Terraform example
bryantbiggs ec47682
chore: update doc wording
bryantbiggs d2f8a08
chore: one last -var reference
bryantbiggs 9ee6224
feat: restrict `iam:PassRole` to only the Karpenter node role
bryantbiggs 4ebf661
fix: remove copy+paste cruft
bryantbiggs 97fc9ba
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 684c747
chore: update to use new sub-module
bryantbiggs 2574bc7
Merge branch 'main' of github.com:bryantbiggs/karpenter into fix/rest…
bryantbiggs a3d6bf7
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 36d1b41
chore: re-update and validate
bryantbiggs f69fb32
chore: remove cloudformation/eksctl changes and v0.6.4 changes
bryantbiggs e69ef7a
chore: align cluster name with other examples
bryantbiggs f4411ce
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs c1500af
chore: updates from testing
bryantbiggs 5f1f22e
chore: final update with latest module changes incorporated for Karpe…
bryantbiggs be7250c
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 98b54c4
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 3b53b83
chore: update terraform modules to current latest
bryantbiggs 83398c6
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs b060ee5
feat: create Karpenter provisioner using Terraform+kubectl
bryantbiggs a937b8e
fix: add required provider versions for 3rd party source resolution
bryantbiggs fd8df73
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 67e2950
Update website/content/en/preview/getting-started/getting-started-wit…
bryantbiggs 2653df1
Merge branch 'main' of github.com:aws/karpenter into fix/restrict-ssm…
bryantbiggs 8576324
docs: add note to udate local kubeconfig before running kubectl commands
bryantbiggs File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.