aws: scope Karpenter controller IAM permissions - #18582
Merged
kubernetes-prow[bot] merged 2 commits intoJul 13, 2026
Merged
Conversation
Member
Author
|
/test pull-kops-scenario-aws-karpenter |
hakman
force-pushed
the
karpenter-iam-scoping
branch
from
July 12, 2026 06:53
cecec8c to
4cbe13b
Compare
hakman
force-pushed
the
karpenter-iam-scoping
branch
from
July 12, 2026 07:13
4cbe13b to
72750f8
Compare
Scope the mutating actions of the Karpenter controller policy, following the upstream reference policy: * iam:PassRole is limited to the worker node role and to the EC2 service. For instance groups that use a custom IAM instance profile, granting iam:PassRole on the role it contains is the responsibility of whoever manages that profile. * ec2:RunInstances, ec2:CreateFleet and ec2:CreateLaunchTemplate require the created resources to be tagged with the cluster tag and the karpenter.sh/nodepool tag, with an unconditional resource-scoped statement for the untagged resources they reference (AMI, snapshots, subnets, security groups, capacity reservations). * ec2:TerminateInstances, ec2:DeleteLaunchTemplate, ec2:CreateTags and ec2:DeleteTags are only allowed on resources with the cluster tag and the karpenter.sh/nodepool tag. * The instance profile mutations are removed, as kOps supplies the instance profile through the EC2NodeClass spec, so Karpenter never creates or mutates instance profiles. Read-only actions remain unconditional.
hakman
force-pushed
the
karpenter-iam-scoping
branch
from
July 12, 2026 07:16
72750f8 to
1647409
Compare
Member
Author
|
/test pull-kops-scenario-aws-karpenter |
Member
Author
|
/test pull-kops-e2e-azure-cni-cilium |
rifelpet
reviewed
Jul 12, 2026
Comment on lines
+1177
to
+1178
| nodeRole := truncate.TruncateString("nodes."+p.clusterName, truncate.TruncateStringOptions{MaxLength: MaxLengthIAMRoleName, AlwaysAddHash: false}) | ||
| passRoleResource := fmt.Sprintf("arn:%s:iam::*:role/%s", p.partition, nodeRole) |
Member
There was a problem hiding this comment.
Users can override this with ig.Spec.IAM.Profile
hakman
force-pushed
the
karpenter-iam-scoping
branch
from
July 13, 2026 03:51
1647409 to
f90616e
Compare
Instance groups with custom IAM instance profiles contain roles with names that kOps cannot predict. When a Karpenter-managed instance group uses one, allow the Karpenter controller to pass any role to EC2.
hakman
force-pushed
the
karpenter-iam-scoping
branch
from
July 13, 2026 04:00
f90616e to
02cfd3f
Compare
Member
Author
|
/test pull-kops-scenario-aws-karpenter |
rifelpet
approved these changes
Jul 13, 2026
Contributor
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rifelpet The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope the mutating actions of the Karpenter controller policy, following the upstream reference policy:
Read-only actions remain unconditional.
/cc @rifelpet @ameukam