mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-07 10:18:54 +00:00
fix(ci): allow CreateServiceLinkedRole on EKS role names (#184)
CreateFargateProfile authorizes the service-linked role by its pathless name before the role exists.
This commit is contained in:
parent
ca174d2322
commit
4e68cf1ccf
1 changed files with 13 additions and 0 deletions
|
|
@ -421,6 +421,19 @@ function iamPolicyDocument(): object {
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
Sid: "ServiceLinkedRoleNames",
|
||||||
|
Effect: "Allow",
|
||||||
|
Action: ["iam:CreateServiceLinkedRole", "iam:TagRole"],
|
||||||
|
Resource: [
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKS`,
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKSForFargate`,
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/AWSServiceRoleForAmazonEKSNodegroup`,
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks.amazonaws.com/*`,
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks-fargate-pods.amazonaws.com/*`,
|
||||||
|
`arn:aws:iam::${ACCOUNT}:role/aws-service-role/eks-nodegroup.amazonaws.com/*`,
|
||||||
|
],
|
||||||
|
},
|
||||||
{
|
{
|
||||||
Sid: "PassAwsServiceRoles",
|
Sid: "PassAwsServiceRoles",
|
||||||
Effect: "Allow",
|
Effect: "Allow",
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue