Skip to content

Commit

Permalink
fix: Insufficient permissions for karpenter policy when not using kar…
Browse files Browse the repository at this point in the history
…penter discovery tags on security group (#294)

Co-authored-by: Arvid Mildner <arvid.mildner@rikstv.no>
Co-authored-by: Bryant Biggs <bryantbiggs@gmail.com>
  • Loading branch information
3 people committed Oct 26, 2022
1 parent 99d64b6 commit 5ad496b
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion modules/iam-role-for-service-accounts-eks/policies.tf
Original file line number Diff line number Diff line change
Expand Up @@ -547,7 +547,6 @@ data "aws_iam_policy_document" "karpenter_controller" {
actions = ["ec2:RunInstances"]
resources = [
"arn:${local.partition}:ec2:*:${local.account_id}:launch-template/*",
"arn:${local.partition}:ec2:*:${local.account_id}:security-group/*",
]

condition {
Expand All @@ -563,6 +562,7 @@ data "aws_iam_policy_document" "karpenter_controller" {
"arn:${local.partition}:ec2:*::image/*",
"arn:${local.partition}:ec2:*:${local.account_id}:instance/*",
"arn:${local.partition}:ec2:*:${local.account_id}:spot-instances-request/*",
"arn:${local.partition}:ec2:*:${local.account_id}:security-group/*",
"arn:${local.partition}:ec2:*:${local.account_id}:volume/*",
"arn:${local.partition}:ec2:*:${local.account_id}:network-interface/*",
"arn:${local.partition}:ec2:*:${coalesce(var.karpenter_subnet_account_id, local.account_id)}:subnet/*",
Expand Down

0 comments on commit 5ad496b

Please sign in to comment.