fix(ci): allow CreateServiceLinkedRole on EKS role names (#184)

CreateFargateProfile authorizes the service-linked role by its pathless name before the role exists.
This commit is contained in:
Adam Moussa 2026-10-05 20:09:46 -04:00 • committed by GitHub
parent ca174d2322
commit 4e68cf1ccf
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -421,6 +421,19 @@ function iamPolicyDocument(): object {
},
},
},
{
Sid: "ServiceLinkedRoleNames",
Effect: "Allow",
Action: ["iam:CreateServiceLinkedRole", "iam:TagRole"],
Resource: [
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKS`,
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKSForFargate`,
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKSNodegroup`,
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks.amazonaws.com/*`,
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks-fargate-pods.amazonaws.com/*`,
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks-nodegroup.amazonaws.com/*`,
],
},
{
Sid: "PassAwsServiceRoles",
Effect: "Allow",