feat (operator): add support for IRSA (aws resources access) (#3128)

* fix data to POSIX and sed working on macos
* add ServiceAccountGetter to the newFakeK8sAnnotationsClient for unit tests
* try to update the service account
* use irsa_role_arn since we need the full arn, and remove enable_irsa
* move sa sync code to existing sync.go file to be all together
* change all Irsa to IRSA to follow go idiomatic that capitalize initialisms or acronyms
* using Update instead of Patch for the service account syn
* document the new option and add the key in the values/configs
* add the new option to the administrator docs
* trying to increase the timeout for the flaky test after sync

---------

Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
Tiago Condeixa
2026-07-15 18:19:10 +02:00
committed by GitHub
co-authored by Felix Kunde
parent 85d7aebab2
commit 7578f9d2c0
17 changed files with 133 additions and 1 deletions
+1
View File
@@ -79,6 +79,7 @@ data:
# inherited_annotations: owned-by
# inherited_labels: application,environment
# kube_iam_role: ""
# irsa_role_arn: ""
kubernetes_use_configmaps: "false"
# log_s3_bucket: ""
# logical_backup_azure_storage_account_name: ""
+2
View File
@@ -73,6 +73,8 @@ spec:
type: integer
gcp_credentials:
type: string
irsa_role_arn:
type: string
kube_iam_role:
type: string
log_s3_bucket:
@@ -171,6 +171,7 @@ configuration:
# enable_ebs_gp3_migration_max_size: 1000
# gcp_credentials: ""
# kube_iam_role: ""
# irsa_role_arn: ""
# log_s3_bucket: ""
# wal_az_storage_account: ""
# wal_gs_bucket: ""