Kubernetes Prow Robot
|
5bfdefb43c
|
Merge pull request #12623 from johngmyers/cilium-ipv6-ipam
Never masquerade IPv6 with Cilium
|
2021-10-29 05:56:51 -07:00 |
John Gardiner Myers
|
7cb4fbe91e
|
Never masquerade IPv6 with Cilium
|
2021-10-27 23:40:02 -07:00 |
Ciprian Hacman
|
a3f4ed7502
|
Update node permissions
|
2021-10-28 07:47:09 +03:00 |
Ole Markus With
|
795ac25363
|
Add permissions needed for KCM to provision NLBs
|
2021-10-26 08:51:28 +02:00 |
Kubernetes Prow Robot
|
af85e5e52e
|
Merge pull request #12309 from olemarkus/lbc-security
Allow AWS LBC to attach certificates
|
2021-10-23 13:16:21 -07:00 |
Peter Rifel
|
7b3fc875f9
|
Add ec2:DescribeLaunchTemplateVersions to CA IAM policy
|
2021-10-20 15:15:06 -07:00 |
John Gardiner Myers
|
8e6214c046
|
Stop requiring the cluster IAM substruct be present
|
2021-10-02 20:18:46 -07:00 |
justinsb
|
db1ba01e94
|
Only add IPv6 IAM permissions if using IPv6
This avoids users wondering what these permissions are for until we
need them.
|
2021-09-18 13:49:40 -04:00 |
Ole Markus With
|
a3a2a9c3bf
|
Have nodeup assign an ipv6 prefix
|
2021-09-16 19:28:07 +02:00 |
Ole Markus With
|
bdad72e9aa
|
Allow AWS LBC to attach certificates
|
2021-09-11 12:50:37 +02:00 |
Ole Markus With
|
4ab75b01cb
|
Have instances learn about their GPU capabilities
|
2021-09-05 20:09:04 +02:00 |
John Gardiner Myers
|
6655022ce1
|
Remove support for the Lyft CNI
|
2021-08-28 11:54:39 -07:00 |
Ole Markus With
|
38f805c5ef
|
Make external-dns a drop-in for dns-controller
Support TXT records
|
2021-08-27 06:24:47 +02:00 |
Peter Rifel
|
3db20bed01
|
./hack/update-expected.sh
|
2021-08-20 08:41:25 -05:00 |
Peter Rifel
|
67007e1a0a
|
Consolidate IAM statements
|
2021-08-19 23:16:04 -05:00 |
Ole Markus With
|
0439bb0d76
|
Remove UseServiceAccountIAM feature flag and rename feature to UseServiceAccountExternalPermissions
|
2021-08-07 21:20:03 +02:00 |
Ole Markus With
|
ce86d851aa
|
IRSA support for CCM
Update pkg/model/components/addonmanifests/awscloudcontroller/iam.go
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
|
2021-08-07 10:27:36 +02:00 |
John Gardiner Myers
|
b94bcafe56
|
Remove unnecessary IAM permission
|
2021-07-23 14:03:41 -07:00 |
Ole Markus With
|
7c448d3535
|
Remove redundant call to addSnapshotPermissions
|
2021-07-19 21:19:05 +02:00 |
Ole Markus With
|
28bd45a8fa
|
Add irsa support for nth
|
2021-07-19 15:12:35 +02:00 |
Ole Markus With
|
f0390eda29
|
Dedicated function for ccm permissons
Update pkg/model/iam/iam_builder.go
Co-authored-by: Peter Rifel <rifelpet@users.noreply.github.com>
|
2021-07-16 19:39:57 +02:00 |
John Gardiner Myers
|
9dbf3479d6
|
Stop writing the certificate-only keyset.yaml
|
2021-07-11 11:16:11 -07:00 |
Ole Markus With
|
a98bfdb64f
|
Allow filefs to be used to mock s3 policies
|
2021-07-04 07:34:56 +02:00 |
Ole Markus With
|
aad2912710
|
Add sets for the remaining addons
|
2021-07-01 10:37:57 +02:00 |
Ole Markus With
|
df5b58b1b3
|
Add sets for the typical default role perms
|
2021-07-01 10:28:01 +02:00 |
Ole Markus With
|
37271998e1
|
Use sets for aws lbc permissions
|
2021-07-01 10:19:40 +02:00 |
Ole Markus With
|
c7bd1c1529
|
Add s3 policies to integration tests
|
2021-07-01 09:26:58 +02:00 |
Ole Markus With
|
9885714957
|
Use NewPolicy for the non-master roles
|
2021-07-01 09:19:35 +02:00 |
Ole Markus With
|
19833e6b73
|
Use sets for ebscsidriver permissions
|
2021-07-01 09:02:04 +02:00 |
Ole Markus With
|
d8bf4dcae1
|
NewPolicy function for instantiating policy struct
|
2021-07-01 08:39:43 +02:00 |
John Gardiner Myers
|
2faf28379a
|
Refactor etcd-client-cilium secrets
|
2021-06-25 23:57:23 -07:00 |
Kubernetes Prow Robot
|
89ad2bc453
|
Merge pull request #11810 from hakman/ipv6_disable_calico_awssrcdstcheck
Enable cross-subnet mode with Calico by default
|
2021-06-25 01:08:45 -07:00 |
Ciprian Hacman
|
a12b3145ee
|
Enable cross-subnet mode with Calico by default
|
2021-06-25 07:13:20 +03:00 |
Kubernetes Prow Robot
|
17c2edc3a1
|
Merge pull request #11811 from olemarkus/ebs-bump
Add back createvolume to master + bump ebs driver
|
2021-06-21 02:19:03 -07:00 |
Kubernetes Prow Robot
|
eb7ba5e943
|
Merge pull request #9229 from johngmyers/version-fullcluster
Put versioned API of cluster into state store
|
2021-06-21 01:32:52 -07:00 |
Ole Markus With
|
79a2c111f2
|
Remove redundant permissions
|
2021-06-21 08:59:54 +02:00 |
Ole Markus With
|
b3f274e140
|
Apply permissions to master role when irsa is not used
|
2021-06-21 08:56:11 +02:00 |
Ole Markus With
|
778323eec9
|
Add missing lbc permission
|
2021-06-19 20:03:40 +02:00 |
Ole Markus With
|
b37bc7578e
|
Reduce master policy size for lb controller
|
2021-06-19 10:12:22 +02:00 |
Kubernetes Prow Robot
|
135cdf3461
|
Merge pull request #11789 from johngmyers/seed-rng
Seed the random number generator on AWS
|
2021-06-18 08:48:06 -07:00 |
Ole Markus With
|
33a7de60a7
|
Enable IRSA for EBS CSI Driver
|
2021-06-18 08:05:59 +02:00 |
John Gardiner Myers
|
42bf3ee85b
|
Seed the random number generator on AWS
|
2021-06-17 22:59:43 -07:00 |
John Gardiner Myers
|
53695fc183
|
Put versioned API of cluster into state store
|
2021-06-16 19:33:46 -07:00 |
Ole Markus With
|
6e8e027aff
|
Enable IRSA for Cluster Autoscaler
|
2021-06-16 18:03:11 +02:00 |
John Gardiner Myers
|
4fe25196d8
|
Trim unnecessary paths from worker node IAM
|
2021-06-15 21:03:13 -07:00 |
Kubernetes Prow Robot
|
cfc93e5178
|
Merge pull request #9294 from johngmyers/refactor-nodeup-context
Remove InstanceGroup from NodeupModelContext
|
2021-06-12 13:43:01 -07:00 |
Matthew Wong
|
4e9b45b324
|
Allow master to touch volumes tagged with kubernetes.io/cluster/<clusterName>:owned
|
2021-06-09 13:52:48 -07:00 |
John Gardiner Myers
|
eb09d31a3c
|
Pass AuxConfig to nodeup
|
2021-06-03 21:04:21 -07:00 |
John Gardiner Myers
|
0a48b9050f
|
Protokube needs dns-controller IAM permissions
|
2021-05-31 06:58:59 -07:00 |
John Gardiner Myers
|
b82b129a54
|
Remove fallback support for legacy IAM
|
2021-05-30 16:52:42 -07:00 |