feat: Add support for EC2 principal in assume worker role policy for China (#827)

* Add support for EC2 principal in assume worker role policy for  China AWS

* Remove local partition  according to requested change

Co-authored-by: Valeri GOLUBEV <vgolubev@kyriba.com>
This commit is contained in:
Valeri GOLUBEV
2020-04-11 14:11:22 +02:00
committed by GitHub
parent eaa4d2c697
commit 2fd078e7c1
4 changed files with 24 additions and 7 deletions

View File

@@ -5,6 +5,7 @@ locals {
worker_ami_name_filter_windows = (var.worker_ami_name_filter_windows != "" ?
var.worker_ami_name_filter_windows : "Windows_Server-2019-English-Core-EKS_Optimized-${tonumber(var.cluster_version) >= 1.14 ? var.cluster_version : 1.14}-*"
)
ec2_principal = "ec2.${data.aws_partition.current.dns_suffix}"
}
data "aws_iam_policy_document" "workers_assume_role_policy" {
@@ -17,7 +18,7 @@ data "aws_iam_policy_document" "workers_assume_role_policy" {
principals {
type = "Service"
identifiers = ["ec2.amazonaws.com"]
identifiers = [local.ec2_principal]
}
}
}