Ole Markus With
|
9d476c0e9c
|
Add CreateSecurityGroup permission for vpcs
|
2022-01-20 17:49:36 +01:00 |
Ole Markus With
|
666cf710a2
|
Push partition into the policy struct
|
2022-01-20 17:49:36 +01:00 |
Ole Markus With
|
0a082fed12
|
Require tag on create for external AWS CCM
|
2022-01-20 15:32:46 +01:00 |
Ciprian Hacman
|
df29b6e406
|
Run hack/update-expected.sh
Signed-off-by: Ciprian Hacman <ciprian@hakman.dev>
|
2022-01-19 13:00:36 +02:00 |
Kubernetes Prow Robot
|
4eb54f2260
|
Merge pull request #13114 from olemarkus/nodeup-describe-regions
Add DescribeRegions to nodeup privs
|
2022-01-18 22:14:05 -08:00 |
Ole Markus With
|
b80488906f
|
Add DescribeRegions to nodeup privs
|
2022-01-17 09:34:29 +01:00 |
Ole Markus With
|
f4e538508f
|
Create helper function for ec2 create/tag-on-create IAM permissions
|
2022-01-14 18:41:28 +01:00 |
Kubernetes Prow Robot
|
2f31054e19
|
Merge pull request #13007 from hakman/skip_non-masquerade-cidr
Use kubelet --non-masquerade-cidr only for Docker with kubenet
|
2021-12-21 18:49:36 -08:00 |
justinsb
|
e8ddfa4328
|
Update test data for bash return change
|
2021-12-20 10:12:07 -05:00 |
Ciprian Hacman
|
b20dfe162a
|
Run hack/update-expected.sh
|
2021-12-20 08:47:25 +02:00 |
Ole Markus With
|
f2f9b9dcbb
|
Determine hostnameOverride entirely in nodeup instead of passing in cloud placeholders from cloudup
|
2021-11-30 13:29:54 +01:00 |
Ciprian Hacman
|
7d34232b4c
|
Run hack/update-expected.sh
|
2021-11-18 07:58:44 +02:00 |
Peter Rifel
|
af426a272b
|
./hack/update-expected.sh
|
2021-11-03 22:17:41 -05:00 |
Peter Rifel
|
c3e8420731
|
Revert "Move some AWS IAM policy actions from tagged conditions to wildcard"
This reverts commit 91e4767851.
|
2021-11-03 21:59:43 -05:00 |
Peter Rifel
|
a8f7fee499
|
./hack/update-expected.sh
|
2021-11-02 20:21:37 -05:00 |
Peter Rifel
|
91e4767851
|
Move some AWS IAM policy actions from tagged conditions to wildcard
I checked these against the IAM docs for each API and moved the actions that dont support tag conditions:
https://docs.aws.amazon.com/service-authorization/latest/reference/list_elasticloadbalancing.html#elasticloadbalancing-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_elasticloadbalancingv2.html#elasticloadbalancingv2-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonec2.html#amazonec2-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonec2autoscaling.html#amazonec2autoscaling-actions-as-permissions
|
2021-11-02 20:06:35 -05:00 |
Peter Rifel
|
8dc11bdba9
|
./hack/update-expected.sh
|
2021-10-29 23:08:28 -05:00 |
Ole Markus With
|
795ac25363
|
Add permissions needed for KCM to provision NLBs
|
2021-10-26 08:51:28 +02:00 |
Peter Rifel
|
e5ca2d1cd6
|
./hack/update-expected.sh
|
2021-10-20 15:15:36 -07:00 |
Ciprian Hacman
|
ff03aed9c5
|
Run hack/update-expected.sh
|
2021-10-04 22:25:16 +03:00 |
Ciprian Hacman
|
729f983c50
|
Run hack/update-expected.sh
|
2021-10-04 20:23:16 +03:00 |
Ciprian Hacman
|
2622964491
|
Run hack/update-expected.sh
|
2021-10-02 07:07:38 +03:00 |
Peter Rifel
|
724804025b
|
./hack/update-expected.sh
|
2021-09-30 09:20:33 -05:00 |
justinsb
|
db1ba01e94
|
Only add IPv6 IAM permissions if using IPv6
This avoids users wondering what these permissions are for until we
need them.
|
2021-09-18 13:49:40 -04:00 |
Ole Markus With
|
a3a2a9c3bf
|
Have nodeup assign an ipv6 prefix
|
2021-09-16 19:28:07 +02:00 |
Ole Markus With
|
4ab75b01cb
|
Have instances learn about their GPU capabilities
|
2021-09-05 20:09:04 +02:00 |
Ole Markus With
|
38f805c5ef
|
Make external-dns a drop-in for dns-controller
Support TXT records
|
2021-08-27 06:24:47 +02:00 |
Peter Rifel
|
3db20bed01
|
./hack/update-expected.sh
|
2021-08-20 08:41:25 -05:00 |
Ole Markus With
|
ce86d851aa
|
IRSA support for CCM
Update pkg/model/components/addonmanifests/awscloudcontroller/iam.go
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
|
2021-08-07 10:27:36 +02:00 |
Ciprian Hacman
|
92ab49cdfb
|
Update Docker to v20.10.8
|
2021-08-04 06:19:43 +03:00 |
Ciprian Hacman
|
541d328812
|
Update containerd to v1.4.9
|
2021-07-30 07:30:42 +03:00 |
Ciprian Hacman
|
b6464658d4
|
Update containerd to v1.4.8
|
2021-07-29 05:27:10 +03:00 |
John Gardiner Myers
|
80eb3c42ac
|
hack/update-expected.sh
|
2021-07-23 14:11:10 -07:00 |
Kubernetes Prow Robot
|
14de757bca
|
Merge pull request #11991 from olemarkus/refactor-iam
Dedicated function for ccm permissons
|
2021-07-16 13:06:10 -07:00 |
Ole Markus With
|
f0390eda29
|
Dedicated function for ccm permissons
Update pkg/model/iam/iam_builder.go
Co-authored-by: Peter Rifel <rifelpet@users.noreply.github.com>
|
2021-07-16 19:39:57 +02:00 |
John Gardiner Myers
|
10692bc2f4
|
hack/update-expected.sh
|
2021-07-14 08:19:10 -07:00 |
Ole Markus With
|
c17ec3a7e7
|
Move containerd config from cloudup to nodeup
|
2021-07-14 10:28:37 +02:00 |
John Gardiner Myers
|
e185c8148d
|
hack/update-expected.sh
|
2021-07-11 11:16:11 -07:00 |
John Gardiner Myers
|
61606868ab
|
hack/update-expected.sh
|
2021-07-10 23:23:13 -07:00 |
John Gardiner Myers
|
a63e65038f
|
hack/update-expected.sh
|
2021-07-10 17:31:59 -07:00 |
John Gardiner Myers
|
86c9ee5506
|
hack/update-expected.sh
|
2021-07-09 00:20:18 -07:00 |
John Gardiner Myers
|
cdf26302b2
|
hack/update-expected.sh
|
2021-07-08 18:46:03 -07:00 |
Kubernetes Prow Robot
|
2e4a1ae143
|
Merge pull request #11921 from johngmyers/rename-k8s-ca
Rename the "ca" keyset to "kubernetes-ca"
|
2021-07-03 21:48:18 -07:00 |
Kubernetes Prow Robot
|
cf834ce5fc
|
Merge pull request #11843 from olemarkus/reduce-policy-size-further
Reduce policy size further
|
2021-07-03 17:58:18 -07:00 |
John Gardiner Myers
|
5834fc2690
|
hack/update-expected.sh
|
2021-07-03 17:33:13 -07:00 |
John Gardiner Myers
|
5c5969d102
|
hack/update-expected.sh
|
2021-07-01 22:25:51 -07:00 |
Ole Markus With
|
aad2912710
|
Add sets for the remaining addons
|
2021-07-01 10:37:57 +02:00 |
Ole Markus With
|
df5b58b1b3
|
Add sets for the typical default role perms
|
2021-07-01 10:28:01 +02:00 |
Ole Markus With
|
37271998e1
|
Use sets for aws lbc permissions
|
2021-07-01 10:19:40 +02:00 |
Ole Markus With
|
c7bd1c1529
|
Add s3 policies to integration tests
|
2021-07-01 09:26:58 +02:00 |