terraform-aws-elasticsearch icon indicating copy to clipboard operation
terraform-aws-elasticsearch copied to clipboard

feat: add possibiblity to use AWS IAM roles for service accounts

Open ghost opened this issue 3 years ago • 3 comments

what

  • To allow usage of AWS IRSA the assume role policy of the created IAM role needs to be adapted, therefore an additional (and optional) statement for the sts:AssumeRoleWithWebIdentity action was added
  • To decouple sts:AssumeRole for the Service and the AWS principal types all statements have been split into separate blocks

why

  • To allow usage of AWS IAM roles inside of EKS AWS
  • more secure than handling AWS access keys and secrets

references

ghost avatar Jul 06 '22 13:07 ghost

Is there an update on this @goruha, can we get this merged?

msvechla avatar May 03 '23 09:05 msvechla

looks promising we are waiting to use this feature in our labs as well , +1 for any merging updates ?

mohramadan911 avatar May 08 '23 15:05 mohramadan911

Thanks @davidsomebody for creating this pull request!

A maintainer will review your changes shortly. Please don't be discouraged if it takes a while.

While you wait, make sure to review our contributor guidelines.

[!TIP]

Need help or want to ask for a PR review to be expedited?

Join us on Slack in the #pr-reviews channel.

mergify[bot] avatar Mar 09 '24 04:03 mergify[bot]