Skip to content

Commit 0732bea

Browse files
authored
feat: Update KMS module to avoid calling data sources when create_kms_key = false (#2804)
1 parent e4c5098 commit 0732bea

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -243,7 +243,7 @@ We are grateful to the community for contributing bugfixes and improvements! Ple
243243
|------|--------|---------|
244244
| <a name="module_eks_managed_node_group"></a> [eks\_managed\_node\_group](#module\_eks\_managed\_node\_group) | ./modules/eks-managed-node-group | n/a |
245245
| <a name="module_fargate_profile"></a> [fargate\_profile](#module\_fargate\_profile) | ./modules/fargate-profile | n/a |
246-
| <a name="module_kms"></a> [kms](#module\_kms) | terraform-aws-modules/kms/aws | 1.1.0 |
246+
| <a name="module_kms"></a> [kms](#module\_kms) | terraform-aws-modules/kms/aws | 2.1.0 |
247247
| <a name="module_self_managed_node_group"></a> [self\_managed\_node\_group](#module\_self\_managed\_node\_group) | ./modules/self-managed-node-group | n/a |
248248

249249
## Resources

main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -122,7 +122,7 @@ resource "aws_cloudwatch_log_group" "this" {
122122

123123
module "kms" {
124124
source = "terraform-aws-modules/kms/aws"
125-
version = "1.1.0" # Note - be mindful of Terraform/provider version compatibility between modules
125+
version = "2.1.0" # Note - be mindful of Terraform/provider version compatibility between modules
126126

127127
create = local.create && var.create_kms_key && local.enable_cluster_encryption_config # not valid on Outposts
128128

modules/karpenter/main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -324,7 +324,7 @@ locals {
324324

325325
iam_role_name = coalesce(var.iam_role_name, "Karpenter-${var.cluster_name}")
326326
iam_role_policy_prefix = "arn:${local.partition}:iam::aws:policy"
327-
cni_policy = var.cluster_ip_family == "ipv6" ? "${local.iam_role_policy_prefix}/AmazonEKS_CNI_IPv6_Policy" : "${local.iam_role_policy_prefix}/AmazonEKS_CNI_Policy"
327+
cni_policy = var.cluster_ip_family == "ipv6" ? "arn:${local.partition}:iam::${local.account_id}:policy/AmazonEKS_CNI_IPv6_Policy" : "${local.iam_role_policy_prefix}/AmazonEKS_CNI_Policy"
328328
}
329329

330330
data "aws_iam_policy_document" "assume_role" {

0 commit comments

Comments
 (0)