eksctl
eksctl copied to clipboard
node instance profile need to include `AmazonEBSCSIDriverPolicy` by default
While using eksctl to create managed nodegroup for k8s 1.23 cluster, I ran into some node instance profile issue, while it is lacking of AmazonEBSCSIDriverPolicy
policy.
Even though I tried to use eksctl to create separate iamserviceaccount
, and use it for aws-ebs-csi-driver
addon, somehow it still references the node instance profile, so I ended up attaching AmazonEBSCSIDriverPolicy
policy into the eks created node instance profile.
Let me know if that makes sense.
https://github.com/eksctl-io/eksctl/blob/9575570b554610129382d0a181645a3806cea98f/pkg/cfn/builder/statement.go#L390-L520
AmazonEBSCSIDriverPolicy is defined entirely here. Have you tried to configure it with what's shown in the doc? https://eksctl.io/usage/iam-policies/?h=ebs#supported-iam-add-on-policies
This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.
This issue was closed because it has been stalled for 5 days with no activity.