Skip to content
This repository was archived by the owner on Feb 22, 2022. It is now read-only.

Conversation

@bouge
Copy link
Contributor

@bouge bouge commented Jan 15, 2020

Add service account annotation and add service account to deployment.

Signed-off-by: Louis Bougeard lbougeard@and.digital

What this PR does / why we need it:

This PR allows for annotations to serviceAccounts to allow for IAM roles for service accounts in EKS rather than having to pass in tokens, instead using a web identity token file.

This relates to: https://groups.google.com/forum/#!topic/prometheus-users/mhn1Z3yG-XA

Special notes for your reviewer:

Checklist

[Place an '[x]' (no spaces) in all applicable fields. Please remove unrelated fields.]

  • DCO signed
  • Chart Version bumped
  • Variables are documented in the README.md
  • Title of the PR starts with chart name (e.g. [stable/mychartname])

bouge added 2 commits January 15, 2020 11:46
Signed-off-by: Louis Bougeard <lbougeard@and.digital>
Signed-off-by: Louis Bougeard <lbougeard@and.digital>
@helm-bot helm-bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. Contribution Allowed If the contributor has signed the DCO or the CNCF CLA (prior to the move to a DCO). labels Jan 15, 2020
@k8s-ci-robot
Copy link
Contributor

Hi @bouge. Thanks for your PR.

I'm waiting for a helm member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@k8s-ci-robot k8s-ci-robot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Jan 15, 2020
Signed-off-by: Louis Bougeard <lbougeard@and.digital>
@bouge
Copy link
Contributor Author

bouge commented Jan 15, 2020

/assign @asherf

@asherf
Copy link
Collaborator

asherf commented Jan 15, 2020

/ok-to-test

@k8s-ci-robot k8s-ci-robot added ok-to-test and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Jan 15, 2020
@bouge
Copy link
Contributor Author

bouge commented Jan 15, 2020

@asherf the test seems to be failing (https://prow.k8s.io/view/gcs/kubernetes-jenkins/pr-logs/pull/helm_charts/20162/pull-charts-e2e/1217470903982493697/), but I don't believe it's related to the changes that the PR makes, do you have any ideas?

@asherf
Copy link
Collaborator

asherf commented Jan 15, 2020

/retest

@bouge
Copy link
Contributor Author

bouge commented Jan 15, 2020

@asherf not ideal, is this because I've bumped the chart version? Happy to spend some time investigating but not really sure what the tests are doing...

@torstenwalter
Copy link
Collaborator

If you show the hidden lines then it reveals the error:

Error creating: pods "prometheus-cloudwatch-exporter-gtjlvmcooy-5797678ccc-" is forbidden: error looking up service account udwatch-exporter-presubmit-20162-1217499848031342594-gtjlvmcooy/prometheus-cloudwatch-exporter: serviceaccount "prometheus-cloudwatch-exporter" not found 10m

You added this condition[{{- if .Values.serviceAccount.create }}which might be the cause.

Signed-off-by: Louis Bougeard <lbougeard@and.digital>
@bouge
Copy link
Contributor Author

bouge commented Jan 16, 2020

/retest

@bouge
Copy link
Contributor Author

bouge commented Jan 16, 2020

@torstenwalter I've moved the logic for that... still failing.

How can I see the logic for the test or run it locally to try and get it to pass?

@torstenwalter
Copy link
Collaborator

The logs show which commands are executed.

Signed-off-by: Louis Bougeard <lbougeard@and.digital>
@bouge
Copy link
Contributor Author

bouge commented Jan 18, 2020

/retest

Signed-off-by: Louis Bougeard <lbougeard@and.digital>
@bouge
Copy link
Contributor Author

bouge commented Jan 20, 2020

@torstenwalter all the tests are now passing, would you be able to review this PR please?

@bouge
Copy link
Contributor Author

bouge commented Jan 22, 2020

@gianrubio @torstenwalter - Any update on this, please?

@asherf
Copy link
Collaborator

asherf commented Jan 22, 2020

/approve

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jan 22, 2020
@asherf
Copy link
Collaborator

asherf commented Jan 22, 2020

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Jan 22, 2020
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: asherf, bouge

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot merged commit 240c575 into helm:master Jan 22, 2020
arturrez pushed a commit to arturrez/stable-charts that referenced this pull request Jan 28, 2020
…ccounts for EKS IAM (helm#20162)

* feat: Add service account annotation and add to deployment

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* bump chart version to 0.6.0

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* fix linting issue

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* move conditions on annotations

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* Use reliable name for creation of service account

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* revert to full name for serviceAccounts

Signed-off-by: Louis Bougeard <lbougeard@and.digital>
Signed-off-by: Artur <artur@upbound.io>
arturrez pushed a commit to arturrez/stable-charts that referenced this pull request Jan 28, 2020
…ccounts for EKS IAM (helm#20162)

* feat: Add service account annotation and add to deployment

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* bump chart version to 0.6.0

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* fix linting issue

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* move conditions on annotations

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* Use reliable name for creation of service account

Signed-off-by: Louis Bougeard <lbougeard@and.digital>

* revert to full name for serviceAccounts

Signed-off-by: Louis Bougeard <lbougeard@and.digital>
Signed-off-by: Artur <artur@upbound.io>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. Contribution Allowed If the contributor has signed the DCO or the CNCF CLA (prior to the move to a DCO). lgtm Indicates that a PR is ready to be merged. ok-to-test size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants