Sitelet https://github.com/kubernetes/kops/commit/205728700eeb05de046ff42203a071a37f4b7baa
Skip to content

Commit 2057287

Browse files
Merge pull request #18600 from hakman/fix-aws-iam-authenticator-addon
nodeup: don't mutate the cluster spec when clearing authenticator config
2 parents 1ab52d5 + 26dcc14 commit 2057287

6 files changed

Lines changed: 49 additions & 13 deletions

‎pkg/apis/nodeup/config.go‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -375,11 +375,13 @@ func NewConfig(cluster *kops.Cluster, instanceGroup *kops.InstanceGroup) (*Confi
375375
},
376376
}
377377
if cluster.Spec.Authentication != nil {
378-
config.APIServerConfig.Authentication = cluster.Spec.Authentication
379-
if cluster.Spec.Authentication.AWS != nil {
378+
// Copy before clearing fields, so that we don't mutate the shared cluster spec.
379+
authentication := *cluster.Spec.Authentication
380+
if authentication.AWS != nil {
380381
// The values go into the manifest and aren't needed by nodeup.
381-
config.APIServerConfig.Authentication.AWS = &kops.AWSAuthenticationSpec{}
382+
authentication.AWS = &kops.AWSAuthenticationSpec{}
382383
}
384+
config.APIServerConfig.Authentication = &authentication
383385
}
384386
if cluster.Spec.API.DNS != nil {
385387
config.APIServerConfig.API.DNS = &kops.DNSAccessSpec{}

‎tests/integration/update_cluster/complex/data/aws_s3_object_cluster-completed.spec_content‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,14 @@ spec:
2323
name: us-test-1a
2424
type: Public
2525
authentication:
26-
aws: {}
26+
aws:
27+
backendMode: CRD
28+
clusterID: complex.example.com
29+
identityMappings:
30+
- arn: arn:aws-test:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
31+
groups:
32+
- he:dev
33+
username: dev:{{SessionNameRaw}}
2734
authorization:
2835
rbac: {}
2936
channel: stable

‎tests/integration/update_cluster/complex/data/aws_s3_object_complex.example.com-addons-authentication.aws-k8s-1.12_content‎

Lines changed: 19 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -155,9 +155,10 @@ spec:
155155
containers:
156156
- args:
157157
- server
158-
- --config=/etc/aws-iam-authenticator/config.yaml
158+
- --cluster-id=complex.example.com
159159
- --state-dir=/var/aws-iam-authenticator
160160
- --kubeconfig-pregenerated=true
161+
- --backend-mode=CRD
161162
image: public.ecr.aws/eks-distro/kubernetes-sigs/aws-iam-authenticator:v0.6.20-eks-1-30-7
162163
livenessProbe:
163164
httpGet:
@@ -180,8 +181,6 @@ spec:
180181
runAsGroup: 10000
181182
runAsUser: 10000
182183
volumeMounts:
183-
- mountPath: /etc/aws-iam-authenticator/
184-
name: config
185184
- mountPath: /var/aws-iam-authenticator/
186185
name: state
187186
- mountPath: /etc/kubernetes/aws-iam-authenticator/
@@ -203,9 +202,6 @@ spec:
203202
- key: CriticalAddonsOnly
204203
operator: Exists
205204
volumes:
206-
- configMap:
207-
name: aws-iam-authenticator
208-
name: config
209205
- hostPath:
210206
path: /srv/kubernetes/aws-iam-authenticator/
211207
name: output
@@ -214,3 +210,20 @@ spec:
214210
name: state
215211
updateStrategy:
216212
type: RollingUpdate
213+
214+
---
215+
216+
apiVersion: iamauthenticator.k8s.aws/v1alpha1
217+
kind: IAMIdentityMapping
218+
metadata:
219+
labels:
220+
addon.kops.k8s.io/name: authentication.aws
221+
app.kubernetes.io/managed-by: kops
222+
k8s-app: aws-iam-authenticator
223+
role.kubernetes.io/authentication: "1"
224+
name: iam-identity-mapping-0
225+
spec:
226+
arn: arn:aws-test:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
227+
groups:
228+
- he:dev
229+
username: dev:{{SessionNameRaw}}

‎tests/integration/update_cluster/complex/data/aws_s3_object_complex.example.com-addons-bootstrap_content‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ spec:
9191
k8s-addon: storage-aws.addons.k8s.io
9292
- id: k8s-1.12
9393
manifest: authentication.aws/k8s-1.12.yaml
94-
manifestHash: 7233a06582f37d422ad0fd908ff5c23965edff21d81e5888549c9ea9089a8309
94+
manifestHash: 22e33f833fccae05f3e7060ea11f4eca26c2a480d8beff874ffda473b6dd0140
9595
name: authentication.aws
9696
selector:
9797
role.kubernetes.io/authentication: "1"

‎tests/integration/update_cluster/complex/in-legacy-v1alpha2.yaml‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,14 @@ spec:
2020
accessLog:
2121
bucket: access-log-example
2222
authentication:
23-
aws: {}
23+
aws:
24+
backendMode: CRD
25+
clusterID: complex.example.com
26+
identityMappings:
27+
- arn: arn:aws-test:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
28+
groups:
29+
- he:dev
30+
username: dev:{{SessionNameRaw}}
2431
kubernetesApiAccess:
2532
- 1.1.1.0/24
2633
- pl-44444444

‎tests/integration/update_cluster/complex/in-v1alpha2.yaml‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,14 @@ spec:
2020
accessLog:
2121
bucket: access-log-example
2222
authentication:
23-
aws: {}
23+
aws:
24+
backendMode: CRD
25+
clusterID: complex.example.com
26+
identityMappings:
27+
- arn: arn:aws-test:iam::000000000000:role/AWSReservedSSO_Developer_7de86b085b6056ae
28+
groups:
29+
- he:dev
30+
username: dev:{{SessionNameRaw}}
2431
kubernetesApiAccess:
2532
- 1.1.1.0/24
2633
- pl-44444444

0 commit comments

Comments
 (0)