Skip to content

Commit 5ad496b

Browse files
apamildnerArvid Mildnerbryantbiggs
authored
fix: Insufficient permissions for karpenter policy when not using karpenter discovery tags on security group (#294)
Co-authored-by: Arvid Mildner <[email protected]> Co-authored-by: Bryant Biggs <[email protected]>
1 parent 99d64b6 commit 5ad496b

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

modules/iam-role-for-service-accounts-eks/policies.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -547,7 +547,6 @@ data "aws_iam_policy_document" "karpenter_controller" {
547547
actions = ["ec2:RunInstances"]
548548
resources = [
549549
"arn:${local.partition}:ec2:*:${local.account_id}:launch-template/*",
550-
"arn:${local.partition}:ec2:*:${local.account_id}:security-group/*",
551550
]
552551

553552
condition {
@@ -563,6 +562,7 @@ data "aws_iam_policy_document" "karpenter_controller" {
563562
"arn:${local.partition}:ec2:*::image/*",
564563
"arn:${local.partition}:ec2:*:${local.account_id}:instance/*",
565564
"arn:${local.partition}:ec2:*:${local.account_id}:spot-instances-request/*",
565+
"arn:${local.partition}:ec2:*:${local.account_id}:security-group/*",
566566
"arn:${local.partition}:ec2:*:${local.account_id}:volume/*",
567567
"arn:${local.partition}:ec2:*:${local.account_id}:network-interface/*",
568568
"arn:${local.partition}:ec2:*:${coalesce(var.karpenter_subnet_account_id, local.account_id)}:subnet/*",

0 commit comments

Comments
 (0)