3 ms·
Why not IRSA + IAM roles with policies to access AWS services?
by __warlord__ 2y ago
Why not IRSA + IAM roles with policies to access AWS services?
- meysamazad 2y agoThat's specific to AWS EKS as far as my understanding goes. This one's targeted at bear-metal Kubernetes.
- thatsmrtalbot 2y agoIts not specific to EKS, you can find the underlying webhook that injects the "identity" here: https://github.com/aws/amazon-eks-pod-identity-webhook https://github.com/aws/amazon-eks-pod-identity-webhook You have to jump through much of the same hoops you describe, having a public `.well-known` endpoint for example. I have achieved this in the past by putting the OIDC discovery information in an S3 bucket.