Peter Rifel
|
c3e8420731
|
Revert "Move some AWS IAM policy actions from tagged conditions to wildcard"
This reverts commit 91e4767851.
|
2021-11-03 21:59:43 -05:00 |
Peter Rifel
|
a8f7fee499
|
./hack/update-expected.sh
|
2021-11-02 20:21:37 -05:00 |
Peter Rifel
|
91e4767851
|
Move some AWS IAM policy actions from tagged conditions to wildcard
I checked these against the IAM docs for each API and moved the actions that dont support tag conditions:
https://docs.aws.amazon.com/service-authorization/latest/reference/list_elasticloadbalancing.html#elasticloadbalancing-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_elasticloadbalancingv2.html#elasticloadbalancingv2-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonec2.html#amazonec2-actions-as-permissions
https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonec2autoscaling.html#amazonec2autoscaling-actions-as-permissions
|
2021-11-02 20:06:35 -05:00 |
Peter Rifel
|
8dc11bdba9
|
./hack/update-expected.sh
|
2021-10-29 23:08:28 -05:00 |
Ole Markus With
|
795ac25363
|
Add permissions needed for KCM to provision NLBs
|
2021-10-26 08:51:28 +02:00 |
Peter Rifel
|
e5ca2d1cd6
|
./hack/update-expected.sh
|
2021-10-20 15:15:36 -07:00 |
Ciprian Hacman
|
ff03aed9c5
|
Run hack/update-expected.sh
|
2021-10-04 22:25:16 +03:00 |
Ciprian Hacman
|
729f983c50
|
Run hack/update-expected.sh
|
2021-10-04 20:23:16 +03:00 |
Ciprian Hacman
|
2622964491
|
Run hack/update-expected.sh
|
2021-10-02 07:07:38 +03:00 |
Peter Rifel
|
724804025b
|
./hack/update-expected.sh
|
2021-09-30 09:20:33 -05:00 |
justinsb
|
db1ba01e94
|
Only add IPv6 IAM permissions if using IPv6
This avoids users wondering what these permissions are for until we
need them.
|
2021-09-18 13:49:40 -04:00 |
Ole Markus With
|
a3a2a9c3bf
|
Have nodeup assign an ipv6 prefix
|
2021-09-16 19:28:07 +02:00 |
Ole Markus With
|
4ab75b01cb
|
Have instances learn about their GPU capabilities
|
2021-09-05 20:09:04 +02:00 |
Ole Markus With
|
38f805c5ef
|
Make external-dns a drop-in for dns-controller
Support TXT records
|
2021-08-27 06:24:47 +02:00 |
Peter Rifel
|
3db20bed01
|
./hack/update-expected.sh
|
2021-08-20 08:41:25 -05:00 |
Ole Markus With
|
ce86d851aa
|
IRSA support for CCM
Update pkg/model/components/addonmanifests/awscloudcontroller/iam.go
Co-authored-by: John Gardiner Myers <jgmyers@proofpoint.com>
|
2021-08-07 10:27:36 +02:00 |
Ciprian Hacman
|
92ab49cdfb
|
Update Docker to v20.10.8
|
2021-08-04 06:19:43 +03:00 |
Ciprian Hacman
|
541d328812
|
Update containerd to v1.4.9
|
2021-07-30 07:30:42 +03:00 |
Ciprian Hacman
|
b6464658d4
|
Update containerd to v1.4.8
|
2021-07-29 05:27:10 +03:00 |
John Gardiner Myers
|
80eb3c42ac
|
hack/update-expected.sh
|
2021-07-23 14:11:10 -07:00 |
Kubernetes Prow Robot
|
14de757bca
|
Merge pull request #11991 from olemarkus/refactor-iam
Dedicated function for ccm permissons
|
2021-07-16 13:06:10 -07:00 |
Ole Markus With
|
f0390eda29
|
Dedicated function for ccm permissons
Update pkg/model/iam/iam_builder.go
Co-authored-by: Peter Rifel <rifelpet@users.noreply.github.com>
|
2021-07-16 19:39:57 +02:00 |
John Gardiner Myers
|
10692bc2f4
|
hack/update-expected.sh
|
2021-07-14 08:19:10 -07:00 |
Ole Markus With
|
c17ec3a7e7
|
Move containerd config from cloudup to nodeup
|
2021-07-14 10:28:37 +02:00 |
John Gardiner Myers
|
e185c8148d
|
hack/update-expected.sh
|
2021-07-11 11:16:11 -07:00 |
John Gardiner Myers
|
61606868ab
|
hack/update-expected.sh
|
2021-07-10 23:23:13 -07:00 |
John Gardiner Myers
|
a63e65038f
|
hack/update-expected.sh
|
2021-07-10 17:31:59 -07:00 |
John Gardiner Myers
|
86c9ee5506
|
hack/update-expected.sh
|
2021-07-09 00:20:18 -07:00 |
John Gardiner Myers
|
cdf26302b2
|
hack/update-expected.sh
|
2021-07-08 18:46:03 -07:00 |
Kubernetes Prow Robot
|
2e4a1ae143
|
Merge pull request #11921 from johngmyers/rename-k8s-ca
Rename the "ca" keyset to "kubernetes-ca"
|
2021-07-03 21:48:18 -07:00 |
Kubernetes Prow Robot
|
cf834ce5fc
|
Merge pull request #11843 from olemarkus/reduce-policy-size-further
Reduce policy size further
|
2021-07-03 17:58:18 -07:00 |
John Gardiner Myers
|
5834fc2690
|
hack/update-expected.sh
|
2021-07-03 17:33:13 -07:00 |
John Gardiner Myers
|
5c5969d102
|
hack/update-expected.sh
|
2021-07-01 22:25:51 -07:00 |
Ole Markus With
|
aad2912710
|
Add sets for the remaining addons
|
2021-07-01 10:37:57 +02:00 |
Ole Markus With
|
df5b58b1b3
|
Add sets for the typical default role perms
|
2021-07-01 10:28:01 +02:00 |
Ole Markus With
|
37271998e1
|
Use sets for aws lbc permissions
|
2021-07-01 10:19:40 +02:00 |
Ole Markus With
|
c7bd1c1529
|
Add s3 policies to integration tests
|
2021-07-01 09:26:58 +02:00 |
Ole Markus With
|
19833e6b73
|
Use sets for ebscsidriver permissions
|
2021-07-01 09:02:04 +02:00 |
John Gardiner Myers
|
0f1de5cfc8
|
hack/update-expected.sh
|
2021-06-30 18:55:35 -07:00 |
Kubernetes Prow Robot
|
ee048e89e7
|
Merge pull request #11872 from johngmyers/refactor-serviceaccount
Refactor nodeup APIServer builder, part one
|
2021-06-28 10:42:01 -07:00 |
John Gardiner Myers
|
7dfe9d82ab
|
hack/update-expected.sh
|
2021-06-27 08:45:06 -07:00 |
John Gardiner Myers
|
fdf034058d
|
hack/update-expected.sh
|
2021-06-27 08:45:05 -07:00 |
Ciprian Hacman
|
348eed772a
|
Avoid spurious changes for ASG InstanceProtection and LT InstanceMonitoring
|
2021-06-27 10:08:13 +03:00 |
John Gardiner Myers
|
89209df150
|
hack/update-expected.sh
|
2021-06-25 22:25:50 -07:00 |
Ciprian Hacman
|
d7f405f65a
|
Decrease default values for net.ipv4.tcp_rmem and net.ipv4.tcp_wmem
|
2021-06-25 21:27:56 +03:00 |
John Gardiner Myers
|
7dea5af9be
|
hack/update-expected.sh
|
2021-06-21 19:37:24 -07:00 |
John Gardiner Myers
|
48c42fe37f
|
hack/update-expected.sh
|
2021-06-21 16:10:07 -07:00 |
Ole Markus With
|
79a2c111f2
|
Remove redundant permissions
|
2021-06-21 08:59:54 +02:00 |
Ole Markus With
|
b3f274e140
|
Apply permissions to master role when irsa is not used
|
2021-06-21 08:56:11 +02:00 |
John Gardiner Myers
|
0700ef64a0
|
hack/update-expected.sh
|
2021-06-19 10:56:24 -07:00 |