mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 05:41:57 +02:00
feat (operator): add support for IRSA (aws resources access) (#3128)
* fix data to POSIX and sed working on macos * add ServiceAccountGetter to the newFakeK8sAnnotationsClient for unit tests * try to update the service account * use irsa_role_arn since we need the full arn, and remove enable_irsa * move sa sync code to existing sync.go file to be all together * change all Irsa to IRSA to follow go idiomatic that capitalize initialisms or acronyms * using Update instead of Patch for the service account syn * document the new option and add the key in the values/configs * add the new option to the administrator docs * trying to increase the timeout for the flaky test after sync --------- Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
co-authored by
Felix Kunde
parent
85d7aebab2
commit
7578f9d2c0
@@ -1094,6 +1094,32 @@ configuration:
|
||||
wal_s3_bucket: your-backup-path
|
||||
```
|
||||
|
||||
Alternatively, if your cluster uses EKS with OIDC, you can use
|
||||
[IRSA](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html)
|
||||
(IAM Roles for Service Accounts) instead of kube2iam. Set `irsa_role_arn` to
|
||||
the full ARN of the IAM role:
|
||||
|
||||
**OperatorConfiguration**
|
||||
|
||||
```yaml
|
||||
apiVersion: "acid.zalan.do/v1"
|
||||
kind: OperatorConfiguration
|
||||
metadata:
|
||||
name: postgresql-operator-configuration
|
||||
configuration:
|
||||
aws_or_gcp:
|
||||
aws_region: eu-central-1
|
||||
irsa_role_arn: arn:aws:iam::123456789012:role/postgres-pod-role
|
||||
wal_s3_bucket: your-backup-path
|
||||
```
|
||||
|
||||
When `irsa_role_arn` is set the operator annotates the pod service account with
|
||||
`eks.amazonaws.com/role-arn` on every reconcile. The EKS OIDC webhook then
|
||||
injects an AWS web identity token into each pod, which takes precedence over
|
||||
the EC2 metadata credentials used by kube2iam. Both `kube_iam_role` and
|
||||
`irsa_role_arn` can coexist during a migration — existing pods retain the
|
||||
kube2iam annotation until they are rotated, at which point only IRSA is used.
|
||||
|
||||
The referenced IAM role should contain the following privileges to make sure
|
||||
Postgres can send compressed WAL files to the given S3 bucket:
|
||||
|
||||
@@ -1204,6 +1230,7 @@ aws_or_gcp:
|
||||
# additional_secret_mount_path: ""
|
||||
# aws_region: eu-central-1
|
||||
# kube_iam_role: ""
|
||||
# irsa_role_arn: ""
|
||||
# log_s3_bucket: ""
|
||||
# wal_s3_bucket: ""
|
||||
wal_gs_bucket: "postgres-backups-bucket-28302F2" # name of bucket on where to save the WAL-E logs
|
||||
@@ -1253,6 +1280,7 @@ aws_or_gcp:
|
||||
additional_secret_mount_path: "/var/secrets/google" # or where ever you want to mount the file
|
||||
# aws_region: eu-central-1
|
||||
# kube_iam_role: ""
|
||||
# irsa_role_arn: ""
|
||||
# log_s3_bucket: ""
|
||||
# wal_s3_bucket: ""
|
||||
wal_gs_bucket: "postgres-backups-bucket-28302F2" # name of bucket on where to save the WAL-E logs
|
||||
|
||||
@@ -798,6 +798,15 @@ yet officially supported.
|
||||
[kube2iam](https://github.com/jtblin/kube2iam) project on AWS. The default is
|
||||
empty.
|
||||
|
||||
* **irsa_role_arn**
|
||||
Full AWS IAM role ARN to supply in the `eks.amazonaws.com/role-arn` annotation
|
||||
of the Postgres pod service account, enabling
|
||||
[IRSA](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html)
|
||||
(IAM Roles for Service Accounts) on EKS. When set, the operator annotates the
|
||||
pod service account on every sync so that the EKS OIDC webhook can inject AWS
|
||||
credentials directly into pods. Must be a full ARN, e.g.
|
||||
`arn:aws:iam::123456789012:role/my-postgres-role`. The default is empty.
|
||||
|
||||
* **aws_region**
|
||||
AWS region used to store EBS volumes. The default is `eu-central-1`. Note,
|
||||
this option is not meant for specifying the AWS region for backups and
|
||||
|
||||
Reference in New Issue
Block a user