diff --git a/terraform/aws/cross_account_iam/README.md b/terraform/aws/cross_account_iam/README.md index 5d374ed..4d46ad5 100644 --- a/terraform/aws/cross_account_iam/README.md +++ b/terraform/aws/cross_account_iam/README.md @@ -51,7 +51,7 @@ Allows the Ditto control plane to create IAM roles within the customer account. Permission boundaries are defined in the `policies/` folder. They constrain the maximum permissions any role created by Ditto can hold. -- `cluster-resources-boundary-policy.json.tpl` — applied to roles accessed by internal cluster services; parameterised with `ec2_project_tag`, the selected VPC ARN, and its subnet IDs. Security-group mutations require the `ditto:project` resource tag, with a VPC-scoped path for load balancer controller operations on untagged node security groups; there is no account-wide mutation allow. EC2 tags may establish the project marker only as part of resource creation; direct tag updates require the marker to exist already. Load-balancer creation and `SetSubnets` require every requested subnet to be one of the selected VPC's subnets while preserving the remaining operations needed to reconcile Kubernetes Services and Ingresses. EC2 actions are explicitly enumerated: reads (Describe*/Get*) for all controllers, plus `CreateFleet`/`CreateLaunchTemplate`/`DeleteLaunchTemplate`/`RunInstances`/`TerminateInstances` for Karpenter. Additional Karpenter services: `ssm:GetParameter` (scoped to EKS/Bottlerocket AMI paths), `sqs:*` (scoped to `karpenter-*` queues), `iam:PassRole` (scoped to CAPA node roles), `eks:DescribeCluster`, `pricing:GetProducts`. `autoscaling:*` is not included — Cluster Autoscaler runs in machine deployment mode and scales via the Kubernetes API, not direct ASG calls. +- `cluster-resources-boundary-policy.json.tpl` — applied to roles accessed by internal cluster services; parameterised with `ec2_project_tag`, the selected VPC ARN, and its subnet IDs. Security-group mutations require the `ditto:project` resource tag, with a VPC-scoped path for load balancer controller operations on untagged node security groups; there is no account-wide mutation allow. EC2 tags may establish the project marker only as part of resource creation; direct tag updates require the marker to exist already. Load-balancer creation and `SetSubnets` require every requested subnet to be one of the selected VPC's subnets while preserving the remaining operations needed to reconcile Kubernetes Services and Ingresses. EC2 actions are explicitly enumerated: reads (Describe*/Get*) for all controllers, plus `CreateFleet`/`CreateLaunchTemplate`/`DeleteLaunchTemplate`/`RunInstances`/`TerminateInstances` for Karpenter. Additional Karpenter services: `ssm:GetParameter` (scoped to EKS/Bottlerocket AMI paths), `sqs:*` (scoped to `karpenter-*` queues), `iam:PassRole` (scoped to CAPA node roles), instance-profile reads (`iam:GetInstanceProfile`/`iam:ListInstanceProfiles`, needed by the Karpenter EC2NodeClass controller and its termination finalizer), `eks:DescribeCluster`, `pricing:GetProducts`. `autoscaling:*` is not included — Cluster Autoscaler runs in machine deployment mode and scales via the Kubernetes API, not direct ASG calls. - `cluster-external-resources-boundary-policy.json` — applied to roles accessed by external cluster services; limited to Secrets Manager write operations: ``` secretsmanager:CreateSecret diff --git a/terraform/aws/cross_account_iam/policies/cluster-resources-boundary-policy.json.tpl b/terraform/aws/cross_account_iam/policies/cluster-resources-boundary-policy.json.tpl index 4ea6703..ba95000 100644 --- a/terraform/aws/cross_account_iam/policies/cluster-resources-boundary-policy.json.tpl +++ b/terraform/aws/cross_account_iam/policies/cluster-resources-boundary-policy.json.tpl @@ -165,6 +165,14 @@ ], "Resource": ${capa_pass_role_resource} }, + { + "Effect": "Allow", + "Action": [ + "iam:GetInstanceProfile", + "iam:ListInstanceProfiles" + ], + "Resource": "arn:aws:iam::*:instance-profile/*" + }, { "Effect": "Allow", "Action": [