feat: Add support for custom IAM role policy (#3087)

This commit is contained in:
Bryant Biggs
2024-07-02 10:56:19 -04:00
committed by GitHub
parent 17448b4782
commit 1604c6cdc8
15 changed files with 314 additions and 1 deletions

View File

@@ -265,6 +265,17 @@ module "eks" {
AmazonEC2ContainerRegistryReadOnly = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly"
additional = aws_iam_policy.node_additional.arn
}
iam_role_policy_statements = [
{
sid = "ECRPullThroughCache"
effect = "Allow"
actions = [
"ecr:CreateRepository",
"ecr:BatchImportUpstreamImage",
]
resources = ["*"]
}
]
launch_template_tags = {
# enable discovery of autoscaling groups by cluster-autoscaler