mirror of https://github.com/kubernetes/kops.git
Merge pull request #6389 from nak3/eks-tag
Add permission for CreateTag on ENI to amazon-vpc-cni-k8s
This commit is contained in:
commit
d9615fcf06
|
@ -363,6 +363,11 @@ $ kops create cluster \
|
|||
"Resource": [
|
||||
"*"
|
||||
]
|
||||
},
|
||||
{
|
||||
"Effect": "Allow",
|
||||
"Action": "ec2:CreateTags",
|
||||
"Resource": "arn:aws:ec2:*:*:network-interface/*"
|
||||
}
|
||||
```
|
||||
|
||||
|
|
|
@ -877,6 +877,13 @@ func addAmazonVPCCNIPermissions(p *Policy, resource stringorslice.StringOrSlice,
|
|||
}),
|
||||
Resource: resource,
|
||||
},
|
||||
&Statement{
|
||||
Effect: StatementEffectAllow,
|
||||
Action: stringorslice.Slice([]string{
|
||||
"ec2:CreateTags",
|
||||
}),
|
||||
Resource: stringorslice.Slice([]string{"arn:aws:ec2:*:*:network-interface/*"}),
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in New Issue