mirror of
https://github.com/ysoftdevs/terraform-aws-eks.git
synced 2026-01-16 16:47:20 +01:00
Add iam:{Create,Delete}OpenIDProviderConnect to required IAM policies (#729)
This commit is contained in:
@@ -14,7 +14,7 @@ project adheres to [Semantic Versioning](http://semver.org/).
|
||||
- [CI] Bump pre-commit-terraform version (by @barryib)
|
||||
- Added example `examples/irsa` for IAM Roles for Service Accounts (by @max-rocket-internet)
|
||||
- **Breaking:** Removal of autoscaling IAM policy and tags (by @max-rocket-internet)
|
||||
- Add `iam:GetOpenIDConnectProvider` grant to the required IAM permissions in `docs/iam-permissions.md` (by @danielelisi)
|
||||
- Add `iam:{Create,Delete,Get}OpenIDConnectProvider` grants to the list of required IAM permissions in `docs/iam-permissions.md` (by @danielelisi)
|
||||
|
||||
#### Important notes
|
||||
|
||||
|
||||
@@ -86,11 +86,13 @@ Following IAM permissions are the minimum permissions needed for your IAM user o
|
||||
"iam:AddRoleToInstanceProfile",
|
||||
"iam:AttachRolePolicy",
|
||||
"iam:CreateInstanceProfile",
|
||||
"iam:CreateOpenIDConnectProvider",
|
||||
"iam:CreateServiceLinkedRole",
|
||||
"iam:CreatePolicy",
|
||||
"iam:CreatePolicyVersion",
|
||||
"iam:CreateRole",
|
||||
"iam:DeleteInstanceProfile",
|
||||
"iam:DeleteOpenIDConnectProvider",
|
||||
"iam:DeletePolicy",
|
||||
"iam:DeleteRole",
|
||||
"iam:DeleteRolePolicy",
|
||||
|
||||
Reference in New Issue
Block a user