A tool for EKS clusters. Leverages AWS IAM Groups and grants them group access in Kubernetes
500K+
The general overview for what this tool does can be found here: https://ygrene.tech/mapping-iam-groups-to-eks-user-access-66fd745a6b77
Have an AWS IAM Group with users that you want to have access to your EKS cluster (https://console.aws.amazon.com/iam/home?#/groups)
Create a new IAM User with an IAM ReadOnly policy
Replace the ACCESS_KEY_ID environment variable in kubernetes/deployment.yaml with your new generated user's access key id
Replace the awsKey: variable in deployment/secret.yaml with the base64 contents of your generated user's secret access key
$ echo -n "secretkey" | base64
Update the AWS_REGION environment variable in kubernetes/deployment.yaml if you aren't running in us-west-2 with your EKS cluster
Edit the kubernetes/deployment.yaml command: with both the IAM group name you want to provide access to, and the Kubernetes group each user in the group should be mapped to.
(there is an example in the manifest already)
Finally:
$ kubectl apply -f kubernetes/
Raise a PR or file an issue, I'd love to help!
Content type
Image
Digest
Size
13.4 MB
Last updated
about 7 years ago
docker pull ygrene/iam-eks-user-mapper