Sitelet https://github.com/kubernetes/kops/pull/18654
Skip to content

Narrow instance cloud permissions to actual consumers - #18654

Merged
kubernetes-prow[bot] merged 5 commits into
kubernetes:masterfrom
hakman:narrow-node-permissions
Aug 1, 2026
Merged

kubernetes-prow[bot] merged 5 commits into
kubernetes:masterfrom
hakman:narrow-node-permissions

Conversation

@hakman

@hakman hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member

The removal of gossip DNS and protokube in kOps 1.37 lets us narrow instance permissions and credentials to their actual consumers.

  • Stop exporting DigitalOcean, Hetzner, and Scaleway API credentials to control-plane user data and the nodeup environment file. Their only node-local consumer was protokube's gossip seed discovery.
  • Omit Route 53 permissions from the AWS control-plane instance role when useServiceAccountExternalPermissions is enabled; dns-controller and external-dns use dedicated service account roles in that mode.
  • Limit kube-router and kindnet ec2:ModifyInstanceAttribute to cluster-tagged instances.
  • Write /etc/sysconfig/kops-configuration with mode 0600.
  • Add kube-router IAM golden coverage and document the changes in the 1.37 release notes.

/cc @rifelpet @ameukam

hakman added 4 commits July 31, 2026 08:50
The DIGITALOCEAN_ACCESS_TOKEN, HCLOUD_TOKEN and SCW_* exports in the
bootstrap script existed only for protokube's gossip seed discovery.
Workers stopped receiving them in kOps 1.36 and protokube itself was
removed in kOps 1.37, so the control-plane exports and their
persistence in /etc/sysconfig/kops-configuration have no consumer
left. All remaining consumers (etcd-manager, kops-controller,
dns-controller, CCM, CSI) receive credentials via manifests built at
kops update time.

Also write /etc/sysconfig/kops-configuration with mode 0600; it can
still contain state store and OpenStack credentials and was
previously world-readable.
Skip the dns-controller Route 53 grant on the control-plane instance
role when useServiceAccountExternalPermissions is set; dns-controller
and external-dns get dedicated IAM roles in that mode, matching how
the other addon permissions are handled.

Scope the kube-router and kindnet ec2:ModifyInstanceAttribute grants
to cluster-tagged instances, matching the CCM and IRSA variants of
the same permission. Add golden coverage for the kube-router node
policy.
@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet July 31, 2026 16:41
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. area/documentation area/nodeup labels Jul 31, 2026
@hakman

hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member Author

/test ?

@hakman

hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-aws-kindnet-debian13

@hakman

hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-kuberouter

@hakman

hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-calico-ipv6

@hakman

hakman commented Jul 31, 2026

Copy link
Copy Markdown
Member Author

/retest

Comment thread docs/releases/1.37-NOTES.md Outdated
# Other changes of note

* TODO
* On DigitalOcean, Hetzner, and Scaleway, control-plane user data no longer includes cloud API credentials. Components that still require them receive them through manifests generated by `kops update cluster`.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Someone could be relying on these in their additionalUserData scripts. Might be worth suggesting how to add them back if desired.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess they would just have to add them to their scripts. Is there a better way?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think thats the only option, should we call that out in this release note?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a small clarification:

If an additionalUserData script or spec.hooks unit relied on these variables, set them in the script or unit itself.

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 31, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 31, 2026
@hakman

hakman commented Aug 1, 2026

Copy link
Copy Markdown
Member Author

/override pull-kops-e2e-cni-cilium-eni

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-cilium-eni

Details

In response to this:

/override pull-kops-e2e-cni-cilium-eni

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow
kubernetes-prow Bot merged commit 9ff72bc into kubernetes:master Aug 1, 2026
39 checks passed
@hakman
hakman deleted the narrow-node-permissions branch August 1, 2026 02:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/documentation area/nodeup cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants