Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion terraform/aws/cross_account_iam/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ Allows the Ditto control plane to create IAM roles within the customer account.

Permission boundaries are defined in the `policies/` folder. They constrain the maximum permissions any role created by Ditto can hold.

- `cluster-resources-boundary-policy.json.tpl` — applied to roles accessed by internal cluster services; parameterised with `ec2_project_tag`, the selected VPC ARN, and its subnet IDs. Security-group mutations require the `ditto:project` resource tag, with a VPC-scoped path for load balancer controller operations on untagged node security groups; there is no account-wide mutation allow. EC2 tags may establish the project marker only as part of resource creation; direct tag updates require the marker to exist already. Load-balancer creation and `SetSubnets` require every requested subnet to be one of the selected VPC's subnets while preserving the remaining operations needed to reconcile Kubernetes Services and Ingresses. EC2 actions are explicitly enumerated: reads (Describe*/Get*) for all controllers, plus `CreateFleet`/`CreateLaunchTemplate`/`DeleteLaunchTemplate`/`RunInstances`/`TerminateInstances` for Karpenter. Additional Karpenter services: `ssm:GetParameter` (scoped to EKS/Bottlerocket AMI paths), `sqs:*` (scoped to `karpenter-*` queues), `iam:PassRole` (scoped to CAPA node roles), `eks:DescribeCluster`, `pricing:GetProducts`. `autoscaling:*` is not included — Cluster Autoscaler runs in machine deployment mode and scales via the Kubernetes API, not direct ASG calls.
- `cluster-resources-boundary-policy.json.tpl` — applied to roles accessed by internal cluster services; parameterised with `ec2_project_tag`, the selected VPC ARN, and its subnet IDs. Security-group mutations require the `ditto:project` resource tag, with a VPC-scoped path for load balancer controller operations on untagged node security groups; there is no account-wide mutation allow. EC2 tags may establish the project marker only as part of resource creation; direct tag updates require the marker to exist already. Load-balancer creation and `SetSubnets` require every requested subnet to be one of the selected VPC's subnets while preserving the remaining operations needed to reconcile Kubernetes Services and Ingresses. EC2 actions are explicitly enumerated: reads (Describe*/Get*) for all controllers, plus `CreateFleet`/`CreateLaunchTemplate`/`DeleteLaunchTemplate`/`RunInstances`/`TerminateInstances` for Karpenter. Additional Karpenter services: `ssm:GetParameter` (scoped to EKS/Bottlerocket AMI paths), `sqs:*` (scoped to `karpenter-*` queues), `iam:PassRole` (scoped to CAPA node roles), instance-profile reads (`iam:GetInstanceProfile`/`iam:ListInstanceProfiles`, needed by the Karpenter EC2NodeClass controller and its termination finalizer), `eks:DescribeCluster`, `pricing:GetProducts`. `autoscaling:*` is not included — Cluster Autoscaler runs in machine deployment mode and scales via the Kubernetes API, not direct ASG calls.
- `cluster-external-resources-boundary-policy.json` — applied to roles accessed by external cluster services; limited to Secrets Manager write operations:
```
secretsmanager:CreateSecret
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -165,6 +165,14 @@
],
"Resource": ${capa_pass_role_resource}
},
{
"Effect": "Allow",
"Action": [
"iam:GetInstanceProfile",
"iam:ListInstanceProfiles"
],
"Resource": "arn:aws:iam::*:instance-profile/*"
},
{
"Effect": "Allow",
"Action": [
Expand Down