Skip to content

Commit 6d48a60

Browse files
authored
Merge pull request #372 from cookpad/coord-e/use-inline-policy-for-v1beta
Use inline policy for v1beta to avoid resource recreation
2 parents 667a032 + a694019 commit 6d48a60

File tree

1 file changed

+8
-8
lines changed

1 file changed

+8
-8
lines changed

modules/karpenter/controller_iam.tf

+8-8
Original file line numberDiff line numberDiff line change
@@ -28,18 +28,18 @@ data "aws_iam_policy_document" "karpenter_controller_assume_role_policy" {
2828
}
2929
}
3030

31-
resource "aws_iam_role_policy_attachment" "karpenter_controller_v1_beta" {
32-
count = var.v1beta ? 1 : 0
33-
role = aws_iam_role.karpenter_controller.id
34-
policy_arn = aws_iam_policy.karpenter_controller_v1_beta[0].arn
35-
}
36-
37-
resource "aws_iam_policy" "karpenter_controller_v1_beta" {
31+
resource "aws_iam_role_policy" "karpenter_controller_v1_beta" {
3832
count = var.v1beta ? 1 : 0
39-
name = "${var.cluster_config.iam_policy_name_prefix}KarpenterController-v1beta-${var.cluster_config.name}"
33+
name = "KarpenterController-v1beta"
34+
role = aws_iam_role.karpenter_controller.id
4035
policy = data.aws_iam_policy_document.karpenter_controller_v1_beta.json
4136
}
4237

38+
moved {
39+
from = aws_iam_role_policy.karpenter_controller_v1_beta
40+
to = aws_iam_role_policy.karpenter_controller_v1_beta[0]
41+
}
42+
4343
data "aws_iam_policy_document" "karpenter_controller_v1_beta" {
4444
statement {
4545
sid = "AllowScopedEC2InstanceAccessActions"

0 commit comments

Comments
 (0)