feat: Kubeconfig file should not be world or group readable by default (#1114)

Co-authored-by: Thierno IB. BARRY <ibrahima.br@gmail.com>
This commit is contained in:
Iryna Shustava
2021-05-27 13:29:17 -07:00
committed by GitHub
parent 7062cd6f94
commit 4a9fc3af11
3 changed files with 8 additions and 1 deletions

View File

@@ -2,6 +2,6 @@ resource "local_file" "kubeconfig" {
count = var.write_kubeconfig && var.create_eks ? 1 : 0
content = local.kubeconfig
filename = substr(var.config_output_path, -1, 1) == "/" ? "${var.config_output_path}kubeconfig_${var.cluster_name}" : var.config_output_path
file_permission = "0644"
file_permission = var.kubeconfig_file_permission
directory_permission = "0755"
}