Skip to content

Commit 517ae6c

Browse files
authored
Merge pull request #5537 from richardcase/5535_missing_permissions
🐛 fix: missing controller permissions
2 parents d2a68a1 + f5c0e0f commit 517ae6c

18 files changed

+89
-16
lines changed

cmd/clusterawsadm/cloudformation/bootstrap/cluster_api_controller.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -151,6 +151,7 @@ func (t Template) ControllersPolicy() *iamv1.PolicyDocument {
151151
"ec2:RevokeSecurityGroupIngress",
152152
"ec2:RunInstances",
153153
"ec2:TerminateInstances",
154+
"ec2:GetSecurityGroupsForVpc",
154155
"tag:GetResources",
155156
"elasticloadbalancing:AddTags",
156157
"elasticloadbalancing:CreateLoadBalancer",
@@ -174,6 +175,7 @@ func (t Template) ControllersPolicy() *iamv1.PolicyDocument {
174175
"elasticloadbalancing:CreateListener",
175176
"elasticloadbalancing:DescribeTargetHealth",
176177
"elasticloadbalancing:RegisterTargets",
178+
"elasticloadbalancing:DeregisterTargets",
177179
"elasticloadbalancing:DeleteListener",
178180
"autoscaling:DescribeAutoScalingGroups",
179181
"autoscaling:DescribeInstanceRefreshes",

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/customsuffix.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/default.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_all_secret_backends.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -217,6 +217,7 @@ Resources:
217217
- ec2:RevokeSecurityGroupIngress
218218
- ec2:RunInstances
219219
- ec2:TerminateInstances
220+
- ec2:GetSecurityGroupsForVpc
220221
- tag:GetResources
221222
- elasticloadbalancing:AddTags
222223
- elasticloadbalancing:CreateLoadBalancer
@@ -240,6 +241,7 @@ Resources:
240241
- elasticloadbalancing:CreateListener
241242
- elasticloadbalancing:DescribeTargetHealth
242243
- elasticloadbalancing:RegisterTargets
244+
- elasticloadbalancing:DeregisterTargets
243245
- elasticloadbalancing:DeleteListener
244246
- autoscaling:DescribeAutoScalingGroups
245247
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_allow_assume_role.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_bootstrap_user.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -217,6 +217,7 @@ Resources:
217217
- ec2:RevokeSecurityGroupIngress
218218
- ec2:RunInstances
219219
- ec2:TerminateInstances
220+
- ec2:GetSecurityGroupsForVpc
220221
- tag:GetResources
221222
- elasticloadbalancing:AddTags
222223
- elasticloadbalancing:CreateLoadBalancer
@@ -240,6 +241,7 @@ Resources:
240241
- elasticloadbalancing:CreateListener
241242
- elasticloadbalancing:DescribeTargetHealth
242243
- elasticloadbalancing:RegisterTargets
244+
- elasticloadbalancing:DeregisterTargets
243245
- elasticloadbalancing:DeleteListener
244246
- autoscaling:DescribeAutoScalingGroups
245247
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_custom_bootstrap_user.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -217,6 +217,7 @@ Resources:
217217
- ec2:RevokeSecurityGroupIngress
218218
- ec2:RunInstances
219219
- ec2:TerminateInstances
220+
- ec2:GetSecurityGroupsForVpc
220221
- tag:GetResources
221222
- elasticloadbalancing:AddTags
222223
- elasticloadbalancing:CreateLoadBalancer
@@ -240,6 +241,7 @@ Resources:
240241
- elasticloadbalancing:CreateListener
241242
- elasticloadbalancing:DescribeTargetHealth
242243
- elasticloadbalancing:RegisterTargets
244+
- elasticloadbalancing:DeregisterTargets
243245
- elasticloadbalancing:DeleteListener
244246
- autoscaling:DescribeAutoScalingGroups
245247
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_different_instance_profiles.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_eks_console.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

cmd/clusterawsadm/cloudformation/bootstrap/fixtures/with_eks_default_roles.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@ Resources:
211211
- ec2:RevokeSecurityGroupIngress
212212
- ec2:RunInstances
213213
- ec2:TerminateInstances
214+
- ec2:GetSecurityGroupsForVpc
214215
- tag:GetResources
215216
- elasticloadbalancing:AddTags
216217
- elasticloadbalancing:CreateLoadBalancer
@@ -234,6 +235,7 @@ Resources:
234235
- elasticloadbalancing:CreateListener
235236
- elasticloadbalancing:DescribeTargetHealth
236237
- elasticloadbalancing:RegisterTargets
238+
- elasticloadbalancing:DeregisterTargets
237239
- elasticloadbalancing:DeleteListener
238240
- autoscaling:DescribeAutoScalingGroups
239241
- autoscaling:DescribeInstanceRefreshes

0 commit comments

Comments
 (0)