Sitelet https://github.com/kubernetes/kops/pull/18582
Skip to content

aws: scope Karpenter controller IAM permissions - #18582

Merged
kubernetes-prow[bot] merged 2 commits into
kubernetes:masterfrom
hakman:karpenter-iam-scoping
Jul 13, 2026
Merged

kubernetes-prow[bot] merged 2 commits into
kubernetes:masterfrom
hakman:karpenter-iam-scoping

Conversation

@hakman

@hakman hakman commented Jul 12, 2026

Copy link
Copy Markdown
Member

Scope the mutating actions of the Karpenter controller policy, following the upstream reference policy:

  • iam:PassRole is limited to the worker node role and to the EC2 service. When Karpenter-managed instance groups use custom IAM instance profiles, the role names are not predictable, so any role may be passed to EC2.
  • ec2:RunInstances, ec2:CreateFleet and ec2:CreateLaunchTemplate require the created resources to be tagged with the cluster tag and the karpenter.sh/nodepool tag, with an unconditional resource-scoped statement for the untagged resources they reference (AMI, snapshots, subnets, security groups, capacity reservations).
  • ec2:TerminateInstances, ec2:DeleteLaunchTemplate, ec2:CreateTags and ec2:DeleteTags are only allowed on resources with the cluster tag and the karpenter.sh/nodepool tag.
  • The instance profile mutations are removed, as kOps supplies the instance profile through the EC2NodeClass spec, so Karpenter never creates or mutates instance profiles.

Read-only actions remain unconditional.

/cc @rifelpet @ameukam

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet July 12, 2026 06:20
@kubernetes-prow kubernetes-prow Bot added area/provider/aws Issues or PRs related to aws provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 12, 2026
@hakman

hakman commented Jul 12, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-scenario-aws-karpenter

@hakman
hakman force-pushed the karpenter-iam-scoping branch from cecec8c to 4cbe13b Compare July 12, 2026 06:53
@hakman
hakman force-pushed the karpenter-iam-scoping branch from 4cbe13b to 72750f8 Compare July 12, 2026 07:13
@kubernetes-prow kubernetes-prow Bot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 12, 2026
Scope the mutating actions of the Karpenter controller policy, following the
upstream reference policy:

* iam:PassRole is limited to the worker node role and to the EC2 service.
  For instance groups that use a custom IAM instance profile, granting
  iam:PassRole on the role it contains is the responsibility of whoever
  manages that profile.
* ec2:RunInstances, ec2:CreateFleet and ec2:CreateLaunchTemplate require the
  created resources to be tagged with the cluster tag and the
  karpenter.sh/nodepool tag, with an unconditional resource-scoped statement
  for the untagged resources they reference (AMI, snapshots, subnets,
  security groups, capacity reservations).
* ec2:TerminateInstances, ec2:DeleteLaunchTemplate, ec2:CreateTags and
  ec2:DeleteTags are only allowed on resources with the cluster tag and the
  karpenter.sh/nodepool tag.
* The instance profile mutations are removed, as kOps supplies the instance
  profile through the EC2NodeClass spec, so Karpenter never creates or
  mutates instance profiles.

Read-only actions remain unconditional.
@hakman
hakman force-pushed the karpenter-iam-scoping branch from 72750f8 to 1647409 Compare July 12, 2026 07:16
@kubernetes-prow kubernetes-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2026
@hakman

hakman commented Jul 12, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-scenario-aws-karpenter
/retest

@hakman

hakman commented Jul 12, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-azure-cni-cilium

Comment on lines +1177 to +1178
nodeRole := truncate.TruncateString("nodes."+p.clusterName, truncate.TruncateStringOptions{MaxLength: MaxLengthIAMRoleName, AlwaysAddHash: false})
passRoleResource := fmt.Sprintf("arn:%s:iam::*:role/%s", p.partition, nodeRole)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Users can override this with ig.Spec.IAM.Profile

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fair, updated

@hakman
hakman force-pushed the karpenter-iam-scoping branch from 1647409 to f90616e Compare July 13, 2026 03:51
@kubernetes-prow kubernetes-prow Bot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 13, 2026
Instance groups with custom IAM instance profiles contain roles with names
that kOps cannot predict. When a Karpenter-managed instance group uses one,
allow the Karpenter controller to pass any role to EC2.
@hakman
hakman force-pushed the karpenter-iam-scoping branch from f90616e to 02cfd3f Compare July 13, 2026 04:00
@hakman

hakman commented Jul 13, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-scenario-aws-karpenter

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 13, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 13, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 6f13efa into kubernetes:master Jul 13, 2026
40 checks passed
@hakman
hakman deleted the karpenter-iam-scoping branch August 8, 2026 07:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/documentation area/provider/aws Issues or PRs related to aws provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants