Skip to content

Commit d4530ee

Browse files
authored
Merge pull request #1164 from tzneal/document-ebs-csi-helm-feature
document the new helm EBS CSI feaure for disabling mutating permissions
2 parents 3464039 + 6ca7af3 commit d4530ee

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

latest/ug/storage/ebs-csi.adoc

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -249,6 +249,15 @@ Before adding the Amazon EBS driver as an Amazon EKS add-on, confirm that you do
249249
250250
====
251251

252+
[NOTE]
253+
====
254+
255+
By default, the RBAC role used by the EBS CSI has permissions to mutate nodes to support its taint removal feature. Due to limitations of Kubernetes RBAC, this also allows it to mutate any other Node in the cluster.
256+
The Helm chart has a parameter (`node.serviceAccount.disableMutation`) that disables mutating Node RBAC permissions for the ebs-csi-node service account. When enabled, driver features such as taint removal will not function.
257+
258+
====
259+
260+
252261
Alternatively, if you want a self-managed installation of the Amazon EBS CSI driver, see https://github.com/kubernetes-sigs/aws-ebs-csi-driver/blob/master/docs/install.md[Installation] on GitHub.
253262

254263
[#ebs-sample-app]

0 commit comments

Comments
 (0)