Add utils command to migrate to pod identity associations #7343
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
eksctl
introduces a new utils command for migrating existing IAM Roles for service accounts to pod identity associations, i.e.Behind the scenes, the command will apply the following steps:
eks-pod-identity-agent
addon if not already active on the clusterRunning the command without the
--approve
flag will only output a plan consisting of a set of tasks reflecting the steps above, e.g.Additionally, to delete the existing OIDC provider trust relationship from all IAM Roles, run the command with
--remove-oidc-provider-trust-relationship
flag, e.g.Checklist
README.md
, or theuserdocs
directory)area/nodegroup
) and kind (e.g.kind/improvement
)BONUS POINTS checklist: complete for good vibes and maybe prizes?! 🤯