-
Notifications
You must be signed in to change notification settings - Fork 1.8k
OSDOCS-1594 - Adding pod identity webhook content for ROSA #51026
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OSDOCS-1594 - Adding pod identity webhook content for ROSA #51026
Conversation
🤖 Updated build preview is available at: Build log: https://circleci.com/gh/ocpdocs-previewbot/openshift-docs/3686 |
d183388
to
29b740e
Compare
6ce9e7c
to
29dd7f5
Compare
@sjenning and @michaelryanmcneill hi! Can you please review this PR from an SME perspective? Thanks! |
@michaelryanmcneill after some initial testing, I decided to create separate docs Jiras for your requests to add content for the optional annotations and the cross-account IAM permissions. We can address those items later, separately from this PR. The Jiras are as follows:
In my testing, the regional endpoint annotation did not produce the corresponding environment variable in the pod. This might potentially relate to aws/amazon-eks-pod-identity-webhook#123. Additionally, I only have access to one AWS account, so I was not able to test the cross-account permissions functionality. My view is that we should focus on reviewing and publishing the content that I have created for this initial PR and then those items can be tested and added later. In this PR, I have also added some commented out content in relation to the optional annotations for later use. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is a really excellent presentation of a workflow that is not at all trivial to explain.
Most of my feedback here is pretty minor, and some is just checking for my own understanding since I will need to understand this later 🤓 Feel free to ping me on Slack if you want to talk about any of the things I brought up more synchronously.
authentication/assuming-an-aws-iam-role-for-a-service-account.adoc
Outdated
Show resolved
Hide resolved
authentication/assuming-an-aws-iam-role-for-a-service-account.adoc
Outdated
Show resolved
Hide resolved
modules/understanding-pod-identity-webhook-workflow-in-user-defined-projects.adoc
Show resolved
Hide resolved
modules/understanding-pod-identity-webhook-workflow-in-user-defined-projects.adoc
Show resolved
Hide resolved
modules/understanding-pod-identity-webhook-workflow-in-user-defined-projects.adoc
Show resolved
Hide resolved
authentication/assuming-an-aws-iam-role-for-a-service-account.adoc
Outdated
Show resolved
Hide resolved
9c4005a
to
98053ee
Compare
This looks great to me, thanks @pneedle-rh for all your hard work. |
98053ee
to
8b8430c
Compare
8b8430c
to
7d6dff7
Compare
/cherrypick enterprise-4.12 |
/cherrypick enterprise-4.11 |
@pneedle-rh: new pull request created: #52919 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@pneedle-rh: new pull request created: #52920 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
This applies to
main
,enterprise-4.12
andenterprise-4.11
.This relates to https://issues.redhat.com/browse/OSDOCS-1594. The PR adds an "Assuming an AWS IAM role for a service account" page to the ROSA documentation.
The preview is at https://51026--docspreview.netlify.app/openshift-rosa/latest/authentication/assuming-an-aws-iam-role-for-a-service-account.html.