Skip to content

Conversation

@xyzyng
Copy link

@xyzyng xyzyng commented Feb 12, 2026

…ecution role permission to assume to WebIdentity

Issue #, if available:

  1. Karpenter role does not have permission to create ec2 with encrypted volume due to lack of permission on kms key
  2. spark job exeuction role does not have permission to use oidc

Description of changes:

  1. Add necessary permission to karpenter to use kms key for volume encryption
  2. Setup spark execution role to trust spark sa for assuming to WebIdentity

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

…ecution role permission to assume to WebIdentity
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant