Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
why
red-hatresource tag versus the "aws:ResourceTag/red-hat-managed": "true" in this case ?There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@rafael-azevedo : The SQS queues for the spot termination handler are created by HyperShift at runtime specifically for the Node Termination Handler. The red-hat-managed tag is used for infrastructure resources (EC2 instances, security groups, network interfaces) that are created during cluster provisioning and managed as part of the cluster lifecycle.
The red-hat tag is already an established pattern in this same policy for non-infrastructure resources — see the ManagedKMSRestrictedResourceTag and CreateGrantRestricted statements which use aws:ResourceTag/red-hat: true for KMS keys. The SQS queues follow the same pattern since they are operator-managed resources, not cluster infrastructure.