Replies: 4 comments 2 replies
-
Can you share how you are setting up the IAM roles to be used in kpack |
Beta Was this translation helpful? Give feedback.
-
Update: I found that kpack uses the corresponding worker node's role instead of the role associated to the attached serviceaccount via IRSA, to push the ClusterBuilder image. |
Beta Was this translation helpful? Give feedback.
-
To anyone stumbling upon this thread, it seems kpack doesn't support IRSA for ClusterBuilder, the image push permissions are determined by permissions the node |
Beta Was this translation helpful? Give feedback.
-
FWIW - I think that this works now and uses the SA for |
Beta Was this translation helpful? Give feedback.
-
Hey everyone.
I've been trying to use IRSA to authenticate a ClusterBuilder to push builder images to an ECR repo and I keep running into the following error:
I couldn't find more details in☹️
kpack-controller
logs eitherI even tried using
docker-registry
type secret created as follows:and mounted it on the serviceaccount but I still get the same error.
I have verified that the IAM role being used has all the necessary permissions and the target repo exists.
Has anyone else run into this same issue?
Any help would be appreciated 🙏🏻
Beta Was this translation helpful? Give feedback.
All reactions