fix(cross-account-iam): allow instance-profile reads in cluster boundary - #36
Merged
Timothy Colbert (s3than) merged 1 commit intoSep 4, 2026
Conversation
The Karpenter EC2NodeClass termination finalizer calls iam:ListInstanceProfiles with a PathPrefix filter and iam:GetInstanceProfile when deleting a node class. The cluster resources boundary policy granted neither, so controller roles wearing it could delete EC2NodeClasses that then wedged permanently in Terminating (observed on eks-ci-0-ditto with ci-runner-kvm). The boundary renders once per deployment scope (unscoped and ditto-cluster-resources-boundary-<scope> variants) for every cross_account_iam consumer; this widens the ceiling for all of them by two read-only IAM actions. Measured worst case post-change: legacy/default at the maximum 9 vpc_subnet_ids renders 5780 of 6144 chars; scoped mode is capped at 6 subnets and its permanent size-limit test stays green.
Jigar Patel (jiggy-ditto)
approved these changes
Sep 4, 2026
Timothy Colbert (s3than)
deleted the
s3than/20260904-boundary-instance-profile-reads
branch
September 4, 2026 05:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
iam:GetInstanceProfileandiam:ListInstanceProfiles(resourcearn:aws:iam::*:instance-profile/*) to the cluster-resources permissions boundary template, and updates the module README's service enumeration to match.Why
Karpenter's EC2NodeClass termination finalizer calls
iam:ListInstanceProfiles(PathPrefix-filtered) andiam:GetInstanceProfilewhen a node class is deleted. The boundary permittediam:PassRolebut neither read action, so any controller role wearing it had a one-way lifecycle: node classes could be created but never deleted — rendered classes wedge inTerminatingwhile the controller loopsAccessDenied, even when the role's identity policy already grants the actions. Identity policy and boundary must both allow the call.Blast radius
This boundary renders once per deployment scope for every consumer of this module's
cross_account_iamsubmodule — all customer BYOC deployments inherit the change on their next dittocloud upgrade. All consumers gain exactly two read-only IAM actions; the mutation surface is unchanged.Size budget verification
IAM managed policies cap at 6,144 chars. Both real worst cases measured with the new statement included:
variables.tfvalidation): dedicated runscoped_eks_boundary_stays_within_policy_size_limitpasses.terraform test -filter=tests/policy_conditions.tftest.hcl: 15/15 pass at planned HEAD.Rollout
Consumers take the change on upgrade to the next tagged release. After it lands, any wedged EC2NodeClass deletion completes on the controller's next reconcile — no other changes required.