chore(ci): swap to new aws account for rke/eks tests #1339
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Swaps over the eks/rke2 tests to the new AWS commercial account. Points the CI to use the new vpc, state bucket, state lock table provisioned in that account. The base infra is defined in this repo and managed with our spacelift integration.
Additionally for the rke2 workflow, the terraform data filter needs to provide the new owning aws account id (since the AMIs are published in a different account than which the CI runs in). The following secrets will need to be updated/created before this will work (I can provide these out of band and then rerun the test CI):
PERMISSIONS_BOUNDARY_ARN
PERMISSIONS_BOUNDARY_NAME
AWS_COMMERCIAL_ROLE_TO_ASSUME
UDS_IMAGES_AWS_ACCOUNT_ID
Related Issue
Fixes #1287
Type of change
Steps to Validate
Checklist before merging