Skip to content

Commit bbbe0c0

Browse files
authored
fix: Avoid restricting Karpenter RunInstances subnets by tag key (#247)
1 parent 775555c commit bbbe0c0

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

.pre-commit-config.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
repos:
22
- repo: https://github.com/antonbabenko/pre-commit-terraform
3-
rev: v1.68.1
3+
rev: v1.71.0
44
hooks:
55
- id: terraform_fmt
66
- id: terraform_validate

modules/iam-role-for-service-accounts-eks/policies.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -552,7 +552,6 @@ data "aws_iam_policy_document" "karpenter_controller" {
552552
resources = [
553553
"arn:${local.partition}:ec2:*:${local.account_id}:launch-template/*",
554554
"arn:${local.partition}:ec2:*:${local.account_id}:security-group/*",
555-
"arn:${local.partition}:ec2:*:${coalesce(var.karpenter_subnet_account_id, local.account_id)}:subnet/*",
556555
]
557556

558557
condition {
@@ -569,6 +568,7 @@ data "aws_iam_policy_document" "karpenter_controller" {
569568
"arn:${local.partition}:ec2:*:${local.account_id}:instance/*",
570569
"arn:${local.partition}:ec2:*:${local.account_id}:volume/*",
571570
"arn:${local.partition}:ec2:*:${local.account_id}:network-interface/*",
571+
"arn:${local.partition}:ec2:*:${coalesce(var.karpenter_subnet_account_id, local.account_id)}:subnet/*",
572572
]
573573
}
574574

0 commit comments

Comments
 (0)