mirror of https://github.com/kubernetes/kops.git
Merge pull request #14243 from olemarkus/irsa-no-oidc
kOps managed OIDC provider is no longer needed for IRSA
This commit is contained in:
commit
15ab9cfedc
|
|
@ -290,9 +290,6 @@ func validateClusterSpec(spec *kops.ClusterSpec, c *kops.Cluster, fieldPath *fie
|
||||||
}
|
}
|
||||||
|
|
||||||
if len(spec.IAM.ServiceAccountExternalPermissions) > 0 {
|
if len(spec.IAM.ServiceAccountExternalPermissions) > 0 {
|
||||||
if spec.ServiceAccountIssuerDiscovery == nil || !spec.ServiceAccountIssuerDiscovery.EnableAWSOIDCProvider {
|
|
||||||
allErrs = append(allErrs, field.Forbidden(fieldPath.Child("iam", "serviceAccountExternalPermissions"), "serviceAccountExternalPermissions requires AWS OIDC Provider to be enabled"))
|
|
||||||
}
|
|
||||||
allErrs = append(allErrs, validateSAExternalPermissions(spec.IAM.ServiceAccountExternalPermissions, fieldPath.Child("iam", "serviceAccountExternalPermissions"))...)
|
allErrs = append(allErrs, validateSAExternalPermissions(spec.IAM.ServiceAccountExternalPermissions, fieldPath.Child("iam", "serviceAccountExternalPermissions"))...)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue