Sitelet https://github.com/kubernetes/kops/commit/8c869e6ddbd7067c04f7bdf4545320925b90be41
Skip to content

Commit 8c869e6

Browse files
authored
Merge pull request #18253 from kubernetes/automated-cherry-pick-of-#18251-upstream-release-1.35
Automated cherry pick of #18251: aws: skip node S3 permissions when kops-controller serves node config
2 parents 0f5d7b3 + 47f9c50 commit 8c869e6

64 files changed

Lines changed: 1 addition & 757 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎pkg/model/iam/iam_builder.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -463,7 +463,7 @@ func (r *NodeRoleNode) BuildAWSPolicy(b *PolicyBuilder) (*Policy, error) {
463463

464464
b.addNodeupPermissions(p, r.enableLifecycleHookPermissions)
465465

466-
if !b.Cluster.UsesNoneDNS() {
466+
if !model.UseKopsControllerForNodeConfig(b.Cluster) {
467467
if err := b.AddS3Permissions(p); err != nil {
468468
return nil, fmt.Errorf("failed to generate AWS IAM S3 access statements: %v", err)
469469
}

‎pkg/model/iam/tests/iam_builder_node_strict.json‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::kops-tests"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎pkg/model/iam/tests/iam_builder_node_strict_ecr.json‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::kops-tests"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/additionalobjects/data/aws_iam_role_policy_nodes.additionalobjects.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/apiservernodes/data/aws_iam_role_policy_nodes.minimal.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/aws-lb-controller/data/aws_iam_role_policy_nodes.minimal.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/bastionadditional_user-data/data/aws_iam_role_policy_nodes.bastionuserdata.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/cluster-autoscaler-priority-expander-custom/data/aws_iam_role_policy_nodes.cas-priority-expander-custom.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/cluster-autoscaler-priority-expander/data/aws_iam_role_policy_nodes.cas-priority-expander.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

‎tests/integration/update_cluster/complex/data/aws_iam_role_policy_nodes.complex.example.com_policy‎

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,5 @@
11
{
22
"Statement": [
3-
{
4-
"Action": [
5-
"s3:GetBucketLocation",
6-
"s3:GetEncryptionConfiguration",
7-
"s3:ListBucket",
8-
"s3:ListBucketVersions"
9-
],
10-
"Effect": "Allow",
11-
"Resource": [
12-
"arn:aws-test:s3:::placeholder-read-bucket"
13-
]
14-
},
153
{
164
"Action": [
175
"autoscaling:DescribeAutoScalingInstances",

0 commit comments

Comments
 (0)