4 ms·
The app wouldn't build the infrastructure though, a controller on the cluster would. If you're using e.g. kube2iam or kiam, then only the controller would recei
by joseph 7y ago
The app wouldn't build the infrastructure though, a controller on the cluster would. If you're using e.g. kube2iam or kiam, then only the controller would receive permissions. If you're in AWS and the controller uses CloudFormation to provision the resources, you can define a service role that CloudFormation will assume. Then your controller mainly just needs PassRole permissions for the service role, which means you don't need anything close to "root" privileges on your cluster.