mirror of https://github.com/kubernetes/kops.git
Add elasticloadbalancing:DeregisterTargets permission to master policy
Without this permission, controller-manager gets the following error: failed to ensure load balancer for service XXX: Error trying to deregister targets in target group: "AccessDenied: User: arn:aws:sts::XXX:assumed-role/masters... is not authorized to perform: elasticloadbalancing:DeregisterTargets on resource: arn:aws:elasticloadbalancing:XXX
This commit is contained in:
parent
66b9e0e8b0
commit
8132073ad9
|
@ -704,6 +704,7 @@ func addMasterELBPolicies(p *Policy, resource stringorslice.StringOrSlice, legac
|
|||
"elasticloadbalancing:CreateTargetGroup", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DeleteListener", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DeleteTargetGroup", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DeregisterTargets", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DescribeListeners", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DescribeLoadBalancerPolicies", // aws_loadbalancer.go
|
||||
"elasticloadbalancing:DescribeTargetGroups", // aws_loadbalancer.go
|
||||
|
|
|
@ -110,6 +110,7 @@
|
|||
"elasticloadbalancing:CreateTargetGroup",
|
||||
"elasticloadbalancing:DeleteListener",
|
||||
"elasticloadbalancing:DeleteTargetGroup",
|
||||
"elasticloadbalancing:DeregisterTargets",
|
||||
"elasticloadbalancing:DescribeListeners",
|
||||
"elasticloadbalancing:DescribeLoadBalancerPolicies",
|
||||
"elasticloadbalancing:DescribeTargetGroups",
|
||||
|
|
|
@ -110,6 +110,7 @@
|
|||
"elasticloadbalancing:CreateTargetGroup",
|
||||
"elasticloadbalancing:DeleteListener",
|
||||
"elasticloadbalancing:DeleteTargetGroup",
|
||||
"elasticloadbalancing:DeregisterTargets",
|
||||
"elasticloadbalancing:DescribeListeners",
|
||||
"elasticloadbalancing:DescribeLoadBalancerPolicies",
|
||||
"elasticloadbalancing:DescribeTargetGroups",
|
||||
|
|
Loading…
Reference in New Issue