diff --git a/modules/karpenter/main.tf b/modules/karpenter/main.tf index 2133d49..343e38b 100644 --- a/modules/karpenter/main.tf +++ b/modules/karpenter/main.tf @@ -131,6 +131,11 @@ data "aws_iam_policy_document" "irsa" { resources = var.irsa_ssm_parameter_arns } + statement { + actions = ["eks:DescribeCluster"] + resources = ["arn:${local.partition}:eks:*:${local.account_id}:cluster/${var.cluster_name}"] + } + statement { actions = ["iam:PassRole"] resources = [var.create_iam_role ? aws_iam_role.this[0].arn : var.iam_role_arn]